2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11538 | MEDIUM | 5.3 | 0.2% | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token coo... |
| CVE-2026-93764 | MEDIUM | 6.5 | 0.1% | Sep 18, 2026 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level enc... |
| CVE-2026-93763 | MEDIUM | 6.5 | 0.2% | Sep 18, 2026 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that... |
| CVE-2026-93751 | MEDIUM | 6.5 | 0.2% | Sep 18, 2026 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon... |
| CVE-2026-93750 | MEDIUM | 5.9 | 0.4% | Sep 18, 2026 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails t... |
| CVE-2026-93432 | MEDIUM | 6.1 | — | Sep 18, 2026 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails... |
| CVE-2026-92768 | MEDIUM | 5.5 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM... |
| CVE-2026-92747 | MEDIUM | 5 | — | Sep 18, 2026 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running p... |
| CVE-2026-92745 | MEDIUM | 5 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met... |
| CVE-2026-84992 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()... |
| CVE-2026-81182 | MEDIUM | 4.2 | 0.3% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ... |
| CVE-2026-77396 | MEDIUM | 6.9 | 0.2% | Sep 18, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser... |
| CVE-2026-77386 | MEDIUM | 6.5 | 0.6% | Sep 18, 2026 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker cou... |
| CVE-2026-77385 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core... |
| CVE-2026-71537 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Se... |
| CVE-2026-69186 | MEDIUM | 5.3 | 0.5% | Sep 18, 2026 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NS... |
| CVE-2026-64847 | MEDIUM | 6.8 | 0.2% | Sep 18, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri... |
| CVE-2026-93579 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, s... |
| CVE-2026-93534 | MEDIUM | 6.3 | — | Sep 18, 2026 | A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file ap... |
| CVE-2026-93533 | MEDIUM | 6.3 | 1.1% | Sep 18, 2026 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi... |
| CVE-2026-93338 | MEDIUM | 5.3 | 0.3% | Sep 18, 2026 | Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows una... |
| CVE-2026-91147 | MEDIUM | 5.9 | 0.3% | Sep 18, 2026 | A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Serv... |
| CVE-2026-77616 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77610 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77609 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now