2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61633 | LOW | 2 | — | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp... |
| CVE-2026-44639 | LOW | 3.7 | — | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ... |
| CVE-2026-84449 | LOW | 3.7 | 0.3% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() ... |
| CVE-2026-84400 | LOW | 3.1 | 0.1% | Sep 18, 2026 | CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote d... |
| CVE-2026-93676 | LOW | 3.2 | 0.1% | Sep 18, 2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio... |
| CVE-2026-93505 | LOW | 3.5 | — | Sep 18, 2026 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-... |
| CVE-2026-16512 | LOW | 3.1 | — | Sep 18, 2026 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched... |
| CVE-2026-93601 | LOW | 2.2 | 0.2% | Sep 18, 2026 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorr... |
| CVE-2026-93600 | LOW | 2.2 | 0.2% | Sep 18, 2026 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore... |
| CVE-2026-93590 | LOW | 3.7 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec... |
| CVE-2026-93589 | LOW | 3.7 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t... |
| CVE-2026-93588 | LOW | 3.1 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re... |
| CVE-2026-93587 | LOW | 3.3 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU... |
| CVE-2026-93586 | LOW | 2.9 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau... |
| CVE-2026-28199 | LOW | 3.3 | — | Sep 18, 2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly... |
| CVE-2026-21806 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows... |
| CVE-2026-56597 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe... |
| CVE-2026-56595 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he... |
| CVE-2026-40538 | LOW | 3.7 | — | Sep 18, 2026 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager... |
| CVE-2026-13683 | LOW | 2.7 | — | Sep 18, 2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler ... |
| CVE-2026-13666 | LOW | 3.5 | — | Sep 18, 2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Man... |
| CVE-2026-89008 | LOW | 2.7 | — | Sep 18, 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o... |
| CVE-2026-89007 | LOW | 2.7 | — | Sep 18, 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o... |
| CVE-2026-88844 | LOW | 2.7 | — | Sep 18, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c... |
| CVE-2026-84904 | LOW | 3.8 | — | Sep 18, 2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a gro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now