2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59823 | MEDIUM | 5.3 | — | Sep 16, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated ... |
| CVE-2026-92605 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, a... |
| CVE-2026-92416 | MEDIUM | 4.3 | — | Sep 16, 2026 | A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_repo... |
| CVE-2026-92413 | MEDIUM | 4.3 | — | Sep 16, 2026 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is... |
| CVE-2026-88593 | MEDIUM | 6.1 | 0.2% | Sep 16, 2026 | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes ... |
| CVE-2026-84397 | MEDIUM | 5.4 | — | Sep 16, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2026-69147 | MEDIUM | 6.5 | — | Sep 16, 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions ... |
| CVE-2026-18120 | MEDIUM | 5.9 | 0.3% | Sep 16, 2026 | Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invokin... |
| CVE-2026-92603 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that... |
| CVE-2026-92601 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission def... |
| CVE-2026-92600 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysU... |
| CVE-2026-92402 | MEDIUM | 6.3 | 0.4% | Sep 16, 2026 | A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affect... |
| CVE-2026-87028 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint bel... |
| CVE-2026-85732 | MEDIUM | 4.7 | — | Sep 16, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go a... |
| CVE-2026-85386 | MEDIUM | 6.1 | 0.4% | Sep 16, 2026 | Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload quest... |
| CVE-2026-84993 | MEDIUM | 6.5 | — | Sep 16, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 a... |
| CVE-2026-71182 | MEDIUM | 6 | 0.1% | Sep 16, 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin... |
| CVE-2026-71181 | MEDIUM | 6 | 0.1% | Sep 16, 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin... |
| CVE-2026-59944 | MEDIUM | 6.1 | — | Sep 16, 2026 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or... |
| CVE-2026-57173 | MEDIUM | 6.5 | 0.7% | Sep 16, 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v... |
| CVE-2026-92627 | MEDIUM | 4.6 | — | Sep 16, 2026 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a ... |
| CVE-2026-92615 | MEDIUM | 6.6 | — | Sep 16, 2026 | A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-reposito... |
| CVE-2026-76104 | MEDIUM | 5.5 | 0.4% | Sep 16, 2026 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerabi... |
| CVE-2026-26947 | MEDIUM | 6.7 | — | Sep 16, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privileg... |
| CVE-2026-19607 | MEDIUM | 5.3 | — | Sep 16, 2026 | A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now