2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56795 | HIGH | 8.2 | 0.1% | Sep 17, 2026 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A lo... |
| CVE-2026-92987 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on... |
| CVE-2026-92986 | HIGH | 8.8 | — | Sep 17, 2026 | SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attack... |
| CVE-2026-92985 | HIGH | 8.8 | — | Sep 17, 2026 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock... |
| CVE-2026-92984 | HIGH | 8.1 | 0.3% | Sep 17, 2026 | HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone... |
| CVE-2026-92983 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions bec... |
| CVE-2026-87742 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (D... |
| CVE-2026-85077 | HIGH | 8.2 | 0.5% | Sep 17, 2026 | Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 respo... |
| CVE-2026-81446 | HIGH | 7.4 | 0.4% | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab... |
| CVE-2026-81445 | HIGH | 7.2 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit... |
| CVE-2026-80356 | HIGH | 7.3 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Un... |
| CVE-2026-77614 | HIGH | 8.8 | — | Sep 17, 2026 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers... |
| CVE-2026-71538 | HIGH | 8.5 | — | Sep 17, 2026 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Win... |
| CVE-2026-63460 | HIGH | 7.5 | — | Sep 17, 2026 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthentica... |
| CVE-2026-63459 | HIGH | 8.7 | 0.3% | Sep 17, 2026 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/... |
| CVE-2026-26950 | HIGH | 8.1 | — | Sep 17, 2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerabil... |
| CVE-2026-92972 | HIGH | 8.6 | 0.3% | Sep 17, 2026 | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefi... |
| CVE-2026-92971 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop tha... |
| CVE-2026-92970 | HIGH | 8.8 | 0.5% | Sep 17, 2026 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authentic... |
| CVE-2026-92961 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allo... |
| CVE-2026-92959 | HIGH | 7.1 | 0.3% | Sep 17, 2026 | vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.the... |
| CVE-2026-92958 | HIGH | 8.5 | — | Sep 17, 2026 | vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard toge... |
| CVE-2026-92954 | HIGH | 8.6 | 0.3% | Sep 17, 2026 | vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises retu... |
| CVE-2026-92950 | HIGH | 8.6 | — | Sep 17, 2026 | vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary cod... |
| CVE-2026-92942 | HIGH | 7.5 | — | Sep 17, 2026 | vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now