2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82890 | MEDIUM | 5.9 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due t... |
| CVE-2026-81623 | MEDIUM | 6.3 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileg... |
| CVE-2026-77528 | MEDIUM | 5.3 | 0.5% | Sep 18, 2026 | Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, We... |
| CVE-2026-76902 | MEDIUM | 5 | 0.3% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-76901 | MEDIUM | 5.8 | 0.4% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-76900 | MEDIUM | 6.8 | 0.5% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In vers... |
| CVE-2026-76899 | MEDIUM | 5.7 | 0.4% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.... |
| CVE-2026-63646 | MEDIUM | 6.9 | 0.7% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-61822 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() ha... |
| CVE-2026-61723 | MEDIUM | 6.8 | 0.2% | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS par... |
| CVE-2026-61722 | MEDIUM | 6.8 | 0.2% | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS par... |
| CVE-2026-61720 | MEDIUM | 6.2 | 0.2% | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser com... |
| CVE-2026-57224 | MEDIUM | 6.5 | 0.4% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-57222 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-52745 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t... |
| CVE-2026-18869 | MEDIUM | 6.4 | 0.2% | Sep 18, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access inte... |
| CVE-2026-17262 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP... |
| CVE-2026-11722 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vuln... |
| CVE-2026-11711 | MEDIUM | 6.5 | 0.4% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service componen... |
| CVE-2026-11710 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of ... |
| CVE-2026-11549 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerab... |
| CVE-2026-11548 | MEDIUM | 4.8 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vuln... |
| CVE-2026-11540 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the fil... |
| CVE-2026-11539 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX conne... |
| CVE-2026-75892 | MEDIUM | 6.5 | 0.1% | Sep 18, 2026 | In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now