2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77608 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77607 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77606 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77339 | MEDIUM | 5.1 | 0.3% | Sep 18, 2026 | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen... |
| CVE-2026-63406 | MEDIUM | 5.9 | 0.3% | Sep 18, 2026 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemet... |
| CVE-2026-63405 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-... |
| CVE-2026-61795 | MEDIUM | 6.8 | 0.6% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU... |
| CVE-2026-61794 | MEDIUM | 6.8 | 0.6% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida... |
| CVE-2026-93737 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate... |
| CVE-2026-93736 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated att... |
| CVE-2026-93689 | MEDIUM | 5.5 | 0.1% | Sep 18, 2026 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device contro... |
| CVE-2026-93532 | MEDIUM | 6.3 | 0.5% | Sep 18, 2026 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf7... |
| CVE-2026-93531 | MEDIUM | 4.3 | — | Sep 18, 2026 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vu... |
| CVE-2026-86689 | MEDIUM | 5.9 | — | Sep 18, 2026 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ... |
| CVE-2026-84451 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of un... |
| CVE-2026-84450 | MEDIUM | 4.3 | 0.4% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a ... |
| CVE-2026-84448 | MEDIUM | 4 | 0.2% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inli... |
| CVE-2026-81946 | MEDIUM | 4.4 | 0.1% | Sep 18, 2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use ... |
| CVE-2026-81945 | MEDIUM | 6.6 | 0.6% | Sep 18, 2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont... |
| CVE-2026-81943 | MEDIUM | 6.7 | 0.1% | Sep 18, 2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont... |
| CVE-2026-81305 | MEDIUM | 6.8 | 0.2% | Sep 18, 2026 | CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity o... |
| CVE-2026-77960 | MEDIUM | 5.3 | — | Sep 18, 2026 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ... |
| CVE-2026-75883 | MEDIUM | 6.8 | 0.3% | Sep 18, 2026 | The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up t... |
| CVE-2026-65970 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-65969 | MEDIUM | 5.5 | 0.1% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now