2026 CVE Vulnerabilities
65,654 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-98162 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_c... |
| CVE-2026-98161 | — | — | 0.2% | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pme... |
| CVE-2026-98160 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData ... |
| CVE-2026-97865 | HIGH | 7.3 | — | Sep 25, 2026 | A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of ... |
| CVE-2026-97864 | MEDIUM | 5.3 | — | Sep 25, 2026 | A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the ... |
| CVE-2026-97222 | MEDIUM | 5.5 | — | Sep 25, 2026 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed S... |
| CVE-2026-93834 | HIGH | 8.8 | 0.4% | Sep 25, 2026 | A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker... |
| CVE-2026-93647 | CRITICAL | 9.3 | 0.2% | Sep 25, 2026 | An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the messag... |
| CVE-2026-93643 | CRITICAL | 9.8 | 1.0% | Sep 25, 2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported p... |
| CVE-2026-93642 | CRITICAL | 9.3 | 0.2% | Sep 25, 2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipie... |
| CVE-2026-93641 | CRITICAL | 9.3 | 0.3% | Sep 25, 2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipi... |
| CVE-2026-85750 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using... |
| CVE-2026-85542 | HIGH | 8.8 | 2.4% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionalit... |
| CVE-2026-85029 | HIGH | 7.5 | 0.5% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files,... |
| CVE-2026-84893 | HIGH | 7.6 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could ex... |
| CVE-2026-84884 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent fo... |
| CVE-2026-80431 | MEDIUM | 6.8 | 0.1% | Sep 25, 2026 | Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a ... |
| CVE-2026-80430 | MEDIUM | 4.6 | 0.2% | Sep 25, 2026 | Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from ... |
| CVE-2026-100190 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)... |
| CVE-2026-100187 | MEDIUM | 6.9 | — | Sep 25, 2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as val... |
| CVE-2026-100177 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a ... |
| CVE-2026-100176 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported fro... |
| CVE-2026-100174 | MEDIUM | 5.1 | — | Sep 25, 2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS).... |
| CVE-2026-100172 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 t... |
| CVE-2026-100079 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on tea... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now