2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62278 | HIGH | 8.1 | 0.5% | Sep 18, 2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen... |
| CVE-2026-61552 | HIGH | 7.2 | 0.9% | Sep 18, 2026 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta... |
| CVE-2026-61551 | HIGH | 8.6 | 0.9% | Sep 18, 2026 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaus... |
| CVE-2026-33625 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 conta... |
| CVE-2026-32641 | HIGH | 7.5 | 0.9% | Sep 18, 2026 | Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/ht... |
| CVE-2026-93758 | HIGH | 8.1 | 0.4% | Sep 18, 2026 | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a ... |
| CVE-2026-93559 | HIGH | 7.3 | 0.4% | Sep 18, 2026 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff... |
| CVE-2026-91149 | HIGH | 7.5 | — | Sep 18, 2026 | A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustain... |
| CVE-2026-81505 | HIGH | 7.1 | 0.5% | Sep 18, 2026 | Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID}... |
| CVE-2026-77301 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt... |
| CVE-2026-77239 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes... |
| CVE-2026-73863 | HIGH | 7 | 0.4% | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro... |
| CVE-2026-63349 | HIGH | 7 | 0.1% | Sep 18, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In ... |
| CVE-2026-62943 | HIGH | 8.7 | 0.5% | Sep 18, 2026 | btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil... |
| CVE-2026-61833 | HIGH | 8.1 | 0.4% | Sep 18, 2026 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior ... |
| CVE-2026-61672 | HIGH | 7.1 | 0.3% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p... |
| CVE-2026-61548 | HIGH | 8.1 | 0.9% | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS... |
| CVE-2026-58197 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too... |
| CVE-2026-55556 | HIGH | 8.2 | 1.1% | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut... |
| CVE-2026-46655 | HIGH | 7.8 | 0.1% | Sep 18, 2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits... |
| CVE-2026-93690 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely ... |
| CVE-2026-93688 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstra... |
| CVE-2026-93687 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attack... |
| CVE-2026-88259 | HIGH | 7.5 | 0.3% | Sep 18, 2026 | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti... |
| CVE-2026-86520 | HIGH | 7.5 | — | Sep 18, 2026 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now