2026 CVE Vulnerabilities
65,664 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84884 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent fo... |
| CVE-2026-80431 | MEDIUM | 6.8 | 0.1% | Sep 25, 2026 | Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a ... |
| CVE-2026-80430 | MEDIUM | 4.6 | 0.2% | Sep 25, 2026 | Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from ... |
| CVE-2026-100190 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)... |
| CVE-2026-100187 | MEDIUM | 6.9 | — | Sep 25, 2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as val... |
| CVE-2026-100177 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a ... |
| CVE-2026-100176 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported fro... |
| CVE-2026-100174 | MEDIUM | 5.1 | — | Sep 25, 2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS).... |
| CVE-2026-100172 | HIGH | 8.5 | — | Sep 25, 2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 t... |
| CVE-2026-100079 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on tea... |
| CVE-2026-100078 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to functi... |
| CVE-2026-100077 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit Duri... |
| CVE-2026-100076 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks o... |
| CVE-2026-100075 | CRITICAL | 9.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters... |
| CVE-2026-100074 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUN... |
| CVE-2026-100073 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Co... |
| CVE-2026-100072 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() ... |
| CVE-2026-100071 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failur... |
| CVE-2026-100070 | — | — | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrin... |
| CVE-2026-95832 | CRITICAL | 9.3 | 0.2% | Sep 25, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code h... |
| CVE-2026-88421 | HIGH | 7.5 | — | Sep 25, 2026 | Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthentica... |
| CVE-2026-88420 | MEDIUM | 5.4 | 0.2% | Sep 25, 2026 | A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through ... |
| CVE-2026-79153 | HIGH | 7.8 | — | Sep 25, 2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driv... |
| CVE-2026-78902 | MEDIUM | 6.1 | — | Sep 25, 2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via t... |
| CVE-2026-52622 | HIGH | 7.5 | — | Sep 25, 2026 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 befo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now