2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81920 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The rese... |
| CVE-2026-81919 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() ac... |
| CVE-2026-79409 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and th... |
| CVE-2026-73467 | MEDIUM | 6.3 | 0.1% | Sep 15, 2026 | On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal A... |
| CVE-2026-73466 | MEDIUM | 6.3 | 0.1% | Sep 15, 2026 | On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to lo... |
| CVE-2026-73465 | MEDIUM | 6.3 | 0.1% | Sep 15, 2026 | On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear tex... |
| CVE-2026-73451 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Vi... |
| CVE-2026-69216 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-siz... |
| CVE-2026-69214 | MEDIUM | 6.8 | 0.3% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a ... |
| CVE-2026-69212 | MEDIUM | 5.9 | 0.2% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware stri... |
| CVE-2026-69211 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-inf... |
| CVE-2026-69201 | MEDIUM | 5.9 | 0.6% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode ... |
| CVE-2026-58773 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This co... |
| CVE-2026-58767 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th... |
| CVE-2026-58765 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of p... |
| CVE-2026-58755 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the cod... |
| CVE-2026-58751 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could ... |
| CVE-2026-58747 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could ... |
| CVE-2026-58739 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. Th... |
| CVE-2026-58731 | MEDIUM | 6.2 | 0.1% | Sep 15, 2026 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This ... |
| CVE-2026-58726 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to l... |
| CVE-2026-58721 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to lo... |
| CVE-2026-58718 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation... |
| CVE-2026-58716 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to loca... |
| CVE-2026-58698 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now