2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65112 | MEDIUM | 6.5 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource ... |
| CVE-2026-95682 | MEDIUM | 4.8 | — | Sep 22, 2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org orga... |
| CVE-2026-95679 | MEDIUM | 6.9 | — | Sep 22, 2026 | MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build... |
| CVE-2026-95674 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list ... |
| CVE-2026-95671 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element cap... |
| CVE-2026-95667 | MEDIUM | 6.9 | — | Sep 22, 2026 | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_ins... |
| CVE-2026-95666 | MEDIUM | 4.3 | — | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length o... |
| CVE-2026-95665 | MEDIUM | 5.1 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. Th... |
| CVE-2026-95396 | MEDIUM | 4.3 | 0.5% | Sep 22, 2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unk... |
| CVE-2026-93343 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_ven... |
| CVE-2026-93342 | MEDIUM | 5.4 | 0.3% | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate... |
| CVE-2026-93341 | MEDIUM | 4.3 | — | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refu... |
| CVE-2026-95661 | MEDIUM | 5.1 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes v... |
| CVE-2026-95659 | MEDIUM | 4.8 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. T... |
| CVE-2026-95658 | MEDIUM | 6.9 | — | Sep 22, 2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list.... |
| CVE-2026-95273 | MEDIUM | 4.3 | — | Sep 22, 2026 | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of ... |
| CVE-2026-63279 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an ... |
| CVE-2026-63278 | MEDIUM | 6.7 | — | Sep 22, 2026 | URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information c... |
| CVE-2026-63276 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and C... |
| CVE-2026-63275 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hin... |
| CVE-2026-63274 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of ... |
| CVE-2026-63273 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The leng... |
| CVE-2026-63272 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a... |
| CVE-2026-95623 | MEDIUM | 5.6 | — | Sep 22, 2026 | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the in... |
| CVE-2026-92882 | MEDIUM | 5.3 | — | Sep 22, 2026 | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now