2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94491 | HIGH | 7.3 | 0.3% | Sep 22, 2026 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. E... |
| CVE-2026-93712 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the ... |
| CVE-2026-93710 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler ... |
| CVE-2026-94425 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_1400... |
| CVE-2026-94627 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child reque... |
| CVE-2026-94626 | HIGH | 7.5 | 0.6% | Sep 21, 2026 | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi... |
| CVE-2026-94624 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur... |
| CVE-2026-94623 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha... |
| CVE-2026-94622 | HIGH | 7.5 | 0.4% | Sep 21, 2026 | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre... |
| CVE-2026-94540 | HIGH | 7.7 | 0.2% | Sep 21, 2026 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, r... |
| CVE-2026-94535 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows auth... |
| CVE-2026-94534 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allo... |
| CVE-2026-88738 | HIGH | 8.8 | 0.2% | Sep 21, 2026 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload fu... |
| CVE-2026-79079 | HIGH | 7.8 | 0.2% | Sep 21, 2026 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/... |
| CVE-2026-65980 | HIGH | 7.9 | 0.7% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61652 | HIGH | 8.7 | 0.4% | Sep 21, 2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issu... |
| CVE-2026-59814 | HIGH | 7.6 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-55210 | HIGH | 7.4 | 0.4% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-94424 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_14000... |
| CVE-2026-88746 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php. |
| CVE-2026-88411 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 lead... |
| CVE-2026-88410 | HIGH | 7.1 | 0.2% | Sep 21, 2026 | The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected ... |
| CVE-2026-88409 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix functio... |
| CVE-2026-88407 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20... |
| CVE-2026-88406 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses func... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now