2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84447 | HIGH | 7.5 | — | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden referenc... |
| CVE-2026-84446 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list ... |
| CVE-2026-84444 | HIGH | 7.4 | 0.4% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, he... |
| CVE-2026-84398 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An att... |
| CVE-2026-84384 | HIGH | 7.5 | — | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata... |
| CVE-2026-81944 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont... |
| CVE-2026-81942 | HIGH | 8.8 | 1.9% | Sep 18, 2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont... |
| CVE-2026-7006 | HIGH | 7.3 | 0.1% | Sep 18, 2026 | Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege ... |
| CVE-2026-67549 | HIGH | 7.6 | 0.4% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-63638 | HIGH | 8.3 | 0.2% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-63422 | HIGH | 7.8 | 0.1% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-63419 | HIGH | 7.8 | 0.2% | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-54148 | HIGH | 8.1 | 0.6% | Sep 18, 2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid... |
| CVE-2026-11381 | HIGH | 8.8 | — | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i... |
| CVE-2026-11378 | HIGH | 8.8 | 0.6% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-11375 | HIGH | 8.8 | 0.6% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a... |
| CVE-2026-10853 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb... |
| CVE-2026-10751 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati... |
| CVE-2026-10744 | HIGH | 7.5 | — | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote... |
| CVE-2026-10575 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he... |
| CVE-2026-10030 | HIGH | 7.1 | — | Sep 18, 2026 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz... |
| CVE-2026-93659 | HIGH | 8.7 | 0.3% | Sep 18, 2026 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a... |
| CVE-2026-93658 | HIGH | 7 | 0.2% | Sep 18, 2026 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ... |
| CVE-2026-93657 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R... |
| CVE-2026-93652 | HIGH | 7.5 | — | Sep 18, 2026 | Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now