2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100757 | — | — | — | Sep 29, 2026 | Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.... |
| CVE-2026-100756 | — | — | — | Sep 29, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4,... |
| CVE-2026-95520 | HIGH | 7.1 | — | Sep 29, 2026 | A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared R... |
| CVE-2026-87748 | HIGH | 8.8 | — | Sep 29, 2026 | Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This ... |
| CVE-2026-85520 | CRITICAL | 9.3 | — | Sep 29, 2026 | Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the ... |
| CVE-2026-73597 | MEDIUM | 6.5 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (C... |
| CVE-2026-73596 | LOW | 3.8 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource... |
| CVE-2026-73595 | MEDIUM | 4.7 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Downl... |
| CVE-2026-73594 | MEDIUM | 6.4 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Impr... |
| CVE-2026-73593 | LOW | 3 | — | Sep 29, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerabil... |
| CVE-2026-66083 | — | — | — | Sep 29, 2026 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user c... |
| CVE-2026-41875 | MEDIUM | 6.9 | — | Sep 29, 2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special websi... |
| CVE-2026-102507 | MEDIUM | 5.7 | — | Sep 29, 2026 | Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler tha... |
| CVE-2026-102497 | — | — | — | Sep 29, 2026 | The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model grou... |
| CVE-2026-102496 | — | — | — | Sep 29, 2026 | Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a maliciou... |
| CVE-2026-102495 | — | — | — | Sep 29, 2026 | Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make pars... |
| CVE-2026-101266 | LOW | 1.3 | — | Sep 29, 2026 | A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire ch... |
| CVE-2026-95509 | HIGH | 8.8 | — | Sep 29, 2026 | Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buff... |
| CVE-2026-96423 | MEDIUM | 5.5 | — | Sep 29, 2026 | X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96422 | MEDIUM | 5.5 | — | Sep 29, 2026 | Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96421 | MEDIUM | 5.5 | — | Sep 29, 2026 | USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96420 | MEDIUM | 4.7 | — | Sep 29, 2026 | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96419 | MEDIUM | 5.5 | — | Sep 29, 2026 | Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution |
| CVE-2026-96418 | MEDIUM | 5.5 | — | Sep 29, 2026 | TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96417 | MEDIUM | 5.5 | — | Sep 29, 2026 | RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now