2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77620 | HIGH | 8.7 | 0.5% | Sep 22, 2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decom... |
| CVE-2026-77619 | HIGH | 8.7 | 0.5% | Sep 22, 2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit c... |
| CVE-2026-75608 | HIGH | 7.7 | — | Sep 22, 2026 | Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker... |
| CVE-2026-75607 | HIGH | 8.1 | — | Sep 22, 2026 | Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards... |
| CVE-2026-70410 | HIGH | 8.8 | — | Sep 22, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avati... |
| CVE-2026-56681 | HIGH | 7.3 | — | Sep 22, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ... |
| CVE-2026-95500 | HIGH | 7.3 | — | Sep 22, 2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file... |
| CVE-2026-89407 | HIGH | 7.5 | — | Sep 22, 2026 | NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expres... |
| CVE-2026-79314 | HIGH | 8.8 | 0.2% | Sep 22, 2026 | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy... |
| CVE-2026-65179 | HIGH | 8.8 | — | Sep 22, 2026 | NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controll... |
| CVE-2026-65178 | HIGH | 7.8 | — | Sep 22, 2026 | NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can i... |
| CVE-2026-65130 | HIGH | 8 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. ... |
| CVE-2026-65128 | HIGH | 8.8 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A succe... |
| CVE-2026-65121 | HIGH | 8.2 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentic... |
| CVE-2026-65118 | HIGH | 7.5 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate v... |
| CVE-2026-65114 | HIGH | 8.3 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication... |
| CVE-2026-65111 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a... |
| CVE-2026-24267 | HIGH | 7.8 | 0.3% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious dat... |
| CVE-2026-24239 | HIGH | 7.8 | 0.3% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause re... |
| CVE-2026-19915 | HIGH | 7.3 | — | Sep 22, 2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The ... |
| CVE-2026-95499 | HIGH | 7.3 | — | Sep 22, 2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_u... |
| CVE-2026-95619 | HIGH | 7.7 | — | Sep 22, 2026 | A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in... |
| CVE-2026-95271 | HIGH | 7.3 | — | Sep 22, 2026 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_a... |
| CVE-2026-75791 | HIGH | 8.6 | — | Sep 22, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerabi... |
| CVE-2026-89420 | HIGH | 7.1 | — | Sep 22, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obt... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now