2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100504 | HIGH | 7 | — | Sep 26, 2026 | Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 ... |
| CVE-2026-96795 | HIGH | 8.8 | — | Sep 25, 2026 | Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py acc... |
| CVE-2026-57449 | HIGH | 7.1 | — | Sep 25, 2026 | Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authe... |
| CVE-2026-88003 | HIGH | 7.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-71483 | HIGH | 8.5 | — | Sep 25, 2026 | Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected b... |
| CVE-2026-100419 | HIGH | 7 | — | Sep 25, 2026 | gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that al... |
| CVE-2026-91765 | HIGH | 7.5 | — | Sep 25, 2026 | cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated at... |
| CVE-2026-57443 | HIGH | 7.5 | — | Sep 25, 2026 | SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4... |
| CVE-2026-10758 | HIGH | 7.5 | 0.3% | Sep 25, 2026 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap... |
| CVE-2026-100391 | HIGH | 8.2 | — | Sep 25, 2026 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing a... |
| CVE-2026-100390 | HIGH | 7.4 | — | Sep 25, 2026 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded... |
| CVE-2026-100389 | HIGH | 8.1 | — | Sep 25, 2026 | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment ha... |
| CVE-2026-100387 | HIGH | 8.1 | — | Sep 25, 2026 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization tha... |
| CVE-2026-100369 | HIGH | 8.4 | — | Sep 25, 2026 | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs... |
| CVE-2026-5267 | HIGH | 7.5 | — | Sep 25, 2026 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API tha... |
| CVE-2026-100372 | HIGH | 7.2 | — | Sep 25, 2026 | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authent... |
| CVE-2026-100368 | HIGH | 8.4 | — | Sep 25, 2026 | CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide spe... |
| CVE-2026-100310 | HIGH | 7 | — | Sep 25, 2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environmen... |
| CVE-2026-100208 | HIGH | 7.5 | — | Sep 25, 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ... |
| CVE-2026-97060 | HIGH | 7.2 | — | Sep 25, 2026 | X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to m... |
| CVE-2026-84465 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signa... |
| CVE-2026-84464 | HIGH | 7.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source featur... |
| CVE-2026-55214 | HIGH | 8.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store... |
| CVE-2026-53629 | HIGH | 7.1 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ ... |
| CVE-2026-53626 | HIGH | 7.1 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now