2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45234 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-100502 | MEDIUM | 5 | — | Sep 25, 2026 | Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attacker... |
| CVE-2026-100501 | MEDIUM | 6.5 | — | Sep 25, 2026 | Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api... |
| CVE-2026-100419 | HIGH | 7 | 0.1% | Sep 25, 2026 | gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that al... |
| CVE-2026-100418 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that ... |
| CVE-2026-100383 | MEDIUM | 4.8 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-100382 | CRITICAL | 10 | — | Sep 25, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Fo... |
| CVE-2026-100381 | MEDIUM | 5.3 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-9313 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-96879 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki -... |
| CVE-2026-91769 | MEDIUM | 4.3 | 0.1% | Sep 25, 2026 | PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matc... |
| CVE-2026-91767 | MEDIUM | 6.5 | 0.2% | Sep 25, 2026 | php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS... |
| CVE-2026-91766 | MEDIUM | 5.9 | 0.3% | Sep 25, 2026 | When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authori... |
| CVE-2026-91765 | HIGH | 7.5 | 0.5% | Sep 25, 2026 | cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated at... |
| CVE-2026-6103 | MEDIUM | 4.3 | — | Sep 25, 2026 | phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 oc... |
| CVE-2026-57864 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-57443 | HIGH | 7.5 | 0.6% | Sep 25, 2026 | SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4... |
| CVE-2026-17545 | MEDIUM | 6.9 | — | Sep 25, 2026 | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM... |
| CVE-2026-10758 | HIGH | 7.5 | 0.3% | Sep 25, 2026 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap... |
| CVE-2026-100417 | LOW | 3.1 | — | Sep 25, 2026 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests,... |
| CVE-2026-100391 | HIGH | 8.2 | — | Sep 25, 2026 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing a... |
| CVE-2026-100390 | HIGH | 7.4 | — | Sep 25, 2026 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded... |
| CVE-2026-100389 | HIGH | 8.1 | 0.6% | Sep 25, 2026 | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment ha... |
| CVE-2026-100388 | MEDIUM | 5.4 | — | Sep 25, 2026 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages i... |
| CVE-2026-100387 | HIGH | 8.1 | — | Sep 25, 2026 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization tha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now