2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91863 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and ex... |
| CVE-2026-89139 | HIGH | 8.7 | 0.5% | Sep 21, 2026 | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a comput... |
| CVE-2026-87858 | HIGH | 7.2 | 0.4% | Sep 21, 2026 | Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An... |
| CVE-2026-65654 | HIGH | 8.7 | 0.6% | Sep 21, 2026 | github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's la... |
| CVE-2026-65653 | HIGH | 8.7 | 0.7% | Sep 21, 2026 | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-pref... |
| CVE-2026-65652 | HIGH | 8.7 | 0.5% | Sep 21, 2026 | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A n... |
| CVE-2026-65651 | HIGH | 8.7 | 0.6% | Sep 21, 2026 | temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstra... |
| CVE-2026-16652 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated cal... |
| CVE-2026-16651 | HIGH | 8.7 | 0.4% | Sep 21, 2026 | temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents... |
| CVE-2026-92574 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container t... |
| CVE-2026-15801 | HIGH | 8 | 0.3% | Sep 21, 2026 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to ... |
| CVE-2026-47321 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the ... |
| CVE-2026-94146 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file ... |
| CVE-2026-94144 | HIGH | 7.3 | 0.3% | Sep 21, 2026 | A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_... |
| CVE-2026-90860 | HIGH | 7.1 | 0.2% | Sep 21, 2026 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in... |
| CVE-2026-94143 | HIGH | 7.3 | 0.3% | Sep 21, 2026 | A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orde... |
| CVE-2026-94142 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulner... |
| CVE-2026-94139 | HIGH | 7.4 | 1.2% | Sep 21, 2026 | A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an... |
| CVE-2026-94129 | HIGH | 8.8 | — | Sep 21, 2026 | A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105... |
| CVE-2026-94128 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of... |
| CVE-2026-94110 | HIGH | 7.3 | 0.3% | Sep 21, 2026 | A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library ... |
| CVE-2026-94044 | HIGH | 7.3 | 0.4% | Sep 20, 2026 | A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affec... |
| CVE-2026-88855 | HIGH | 8.6 | 0.3% | Sep 20, 2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Jooml... |
| CVE-2026-94039 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /ap... |
| CVE-2026-94038 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now