2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93576 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed ... |
| CVE-2026-93569 | HIGH | 8.2 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 con... |
| CVE-2026-93568 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTT... |
| CVE-2026-93567 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly u... |
| CVE-2026-93565 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes fr... |
| CVE-2026-93564 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticat... |
| CVE-2026-93558 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnera... |
| CVE-2026-77929 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c... |
| CVE-2026-93604 | HIGH | 7.2 | — | Sep 18, 2026 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow... |
| CVE-2026-93599 | HIGH | 7.5 | 0.3% | Sep 18, 2026 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_str... |
| CVE-2026-93598 | HIGH | 7.1 | 0.5% | Sep 18, 2026 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot s... |
| CVE-2026-93597 | HIGH | 7.7 | — | Sep 18, 2026 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and... |
| CVE-2026-93594 | HIGH | 8.1 | — | Sep 18, 2026 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru... |
| CVE-2026-93593 | HIGH | 8.1 | 0.2% | Sep 18, 2026 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b... |
| CVE-2026-93592 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, ... |
| CVE-2026-93591 | HIGH | 7.6 | — | Sep 18, 2026 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values... |
| CVE-2026-93560 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l... |
| CVE-2026-88623 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us... |
| CVE-2026-88622 | HIGH | 8.8 | 1.1% | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. |
| CVE-2026-93491 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli... |
| CVE-2026-93488 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because... |
| CVE-2026-28198 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp... |
| CVE-2026-28197 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr... |
| CVE-2026-93575 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ... |
| CVE-2026-93572 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now