2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55304 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This... |
| CVE-2026-55302 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local ... |
| CVE-2026-19641 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | On affected platforms running Arista EOS with password authentication configured, a specially crafted password can creat... |
| CVE-2026-19504 | MEDIUM | 4 | 0.1% | Sep 15, 2026 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose... |
| CVE-2026-0197 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local informati... |
| CVE-2026-0192 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local e... |
| CVE-2026-0187 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the c... |
| CVE-2026-0186 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could... |
| CVE-2026-0183 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclo... |
| CVE-2026-0179 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalat... |
| CVE-2026-0177 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This cou... |
| CVE-2026-82837 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and... |
| CVE-2026-81237 | MEDIUM | 6.5 | 0.2% | Sep 15, 2026 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthe... |
| CVE-2026-81235 | MEDIUM | 4.9 | 0.1% | Sep 15, 2026 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high p... |
| CVE-2026-57442 | MEDIUM | 6.9 | 0.2% | Sep 15, 2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, ... |
| CVE-2026-56831 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts neg... |
| CVE-2026-56830 | MEDIUM | 6.5 | — | Sep 15, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() ... |
| CVE-2026-55375 | MEDIUM | 5.3 | — | Sep 15, 2026 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQuery... |
| CVE-2026-55374 | MEDIUM | 4.8 | — | Sep 15, 2026 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUr... |
| CVE-2026-55226 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I... |
| CVE-2026-54689 | MEDIUM | 6.3 | 0.1% | Sep 15, 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ... |
| CVE-2026-54688 | MEDIUM | 6.5 | — | Sep 15, 2026 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ... |
| CVE-2026-54050 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/p... |
| CVE-2026-53954 | MEDIUM | 4.3 | — | Sep 15, 2026 | Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied w... |
| CVE-2026-53941 | MEDIUM | 6.9 | 0.4% | Sep 15, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now