2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93382 | HIGH | 8.8 | 0.3% | Sep 17, 2026 | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-93381 | HIGH | 8.8 | 0.3% | Sep 17, 2026 | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging soc... |
| CVE-2026-93377 | HIGH | 8.8 | 0.4% | Sep 17, 2026 | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to ... |
| CVE-2026-93375 | HIGH | 8.1 | 0.1% | Sep 17, 2026 | Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker... |
| CVE-2026-86049 | HIGH | 7.1 | 0.4% | Sep 17, 2026 | Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jup... |
| CVE-2026-77615 | HIGH | 8.7 | 0.6% | Sep 17, 2026 | Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Op... |
| CVE-2026-76154 | HIGH | 7.3 | — | Sep 17, 2026 | A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role... |
| CVE-2026-68537 | HIGH | 7.5 | 0.6% | Sep 17, 2026 | `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve... |
| CVE-2026-68523 | HIGH | 7.5 | 0.6% | Sep 17, 2026 | `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve... |
| CVE-2026-54916 | HIGH | 8.8 | 0.6% | Sep 17, 2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abse... |
| CVE-2026-54597 | HIGH | 8.3 | 0.4% | Sep 17, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi... |
| CVE-2026-54596 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi... |
| CVE-2026-54510 | HIGH | 7.1 | — | Sep 17, 2026 | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the... |
| CVE-2026-54354 | HIGH | 8.2 | 0.7% | Sep 17, 2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran... |
| CVE-2026-54339 | HIGH | 7.7 | 0.5% | Sep 17, 2026 | Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe... |
| CVE-2026-52483 | HIGH | 8.8 | 0.4% | Sep 17, 2026 | The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(... |
| CVE-2026-50277 | HIGH | 7.5 | 0.8% | Sep 17, 2026 | dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggag... |
| CVE-2026-50275 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddt... |
| CVE-2026-48977 | HIGH | 7.7 | 0.3% | Sep 17, 2026 | OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() pro... |
| CVE-2026-15815 | HIGH | 8.8 | 0.9% | Sep 17, 2026 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug... |
| CVE-2026-93337 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows loc... |
| CVE-2026-92943 | HIGH | 8.1 | — | Sep 17, 2026 | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for ... |
| CVE-2026-54716 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earli... |
| CVE-2026-54692 | HIGH | 7.8 | 0.2% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P... |
| CVE-2026-50285 | HIGH | 7.5 | 0.7% | Sep 17, 2026 | Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now