2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93015 | MEDIUM | 6.3 | 0.4% | Sep 17, 2026 | BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream... |
| CVE-2026-93013 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadat... |
| CVE-2026-92881 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory ... |
| CVE-2026-86862 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbn... |
| CVE-2026-86861 | MEDIUM | 5.9 | 0.4% | Sep 17, 2026 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested pat... |
| CVE-2026-86000 | MEDIUM | 5.3 | — | Sep 17, 2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src... |
| CVE-2026-85999 | MEDIUM | 5.3 | 0.4% | Sep 17, 2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soups... |
| CVE-2026-85718 | MEDIUM | 5.9 | — | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-85717 | MEDIUM | 6.8 | 0.3% | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-81868 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-76781 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL po... |
| CVE-2026-75523 | MEDIUM | 5.9 | 0.3% | Sep 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-92880 | MEDIUM | 6.3 | 0.2% | Sep 17, 2026 | A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/c... |
| CVE-2026-85078 | MEDIUM | 6.5 | — | Sep 17, 2026 | Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does... |
| CVE-2026-81447 | MEDIUM | 6.8 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerabil... |
| CVE-2026-63461 | MEDIUM | 5.3 | — | Sep 17, 2026 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and fac... |
| CVE-2026-61793 | MEDIUM | 6.9 | — | Sep 17, 2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthen... |
| CVE-2026-92973 | MEDIUM | 6.1 | 0.2% | Sep 17, 2026 | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that f... |
| CVE-2026-92963 | MEDIUM | 5.3 | — | Sep 17, 2026 | vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL gl... |
| CVE-2026-92952 | MEDIUM | 6.8 | — | Sep 17, 2026 | vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. ... |
| CVE-2026-92949 | MEDIUM | 4 | 0.2% | Sep 17, 2026 | vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowin... |
| CVE-2026-92945 | MEDIUM | 4.2 | — | Sep 17, 2026 | vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix... |
| CVE-2026-92936 | MEDIUM | 5.8 | — | Sep 17, 2026 | vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting.... |
| CVE-2026-92933 | MEDIUM | 5.8 | 0.3% | Sep 17, 2026 | vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the... |
| CVE-2026-92879 | MEDIUM | 4.3 | — | Sep 17, 2026 | A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now