2026 CVE Vulnerabilities
65,828 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-95699 | CRITICAL | 9.6 | 0.3% | Sep 24, 2026 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ... |
| CVE-2026-93353 | MEDIUM | 5.3 | — | Sep 24, 2026 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ... |
| CVE-2026-88388 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ... |
| CVE-2026-88387 | MEDIUM | 5.5 | — | Sep 24, 2026 | LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF ta... |
| CVE-2026-88386 | MEDIUM | 5.5 | 0.1% | Sep 24, 2026 | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec... |
| CVE-2026-87118 | MEDIUM | 5.7 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona... |
| CVE-2026-84403 | MEDIUM | 6.2 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access... |
| CVE-2026-82716 | MEDIUM | 4.6 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag... |
| CVE-2026-82708 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce... |
| CVE-2026-82585 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An at... |
| CVE-2026-81630 | HIGH | 8.1 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce... |
| CVE-2026-79959 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. A... |
| CVE-2026-75558 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi cre... |
| CVE-2026-14443 | HIGH | 8.4 | 0.1% | Sep 24, 2026 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extensio... |
| CVE-2026-14442 | MEDIUM | 6.9 | — | Sep 24, 2026 | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be writt... |
| CVE-2026-14441 | MEDIUM | 6.9 | 0.4% | Sep 24, 2026 | A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when pro... |
| CVE-2026-97365 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file cr... |
| CVE-2026-97326 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this i... |
| CVE-2026-97325 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability ... |
| CVE-2026-97324 | HIGH | 7.3 | — | Sep 24, 2026 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoO... |
| CVE-2026-96883 | HIGH | 8.8 | — | Sep 24, 2026 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 m... |
| CVE-2026-93354 | HIGH | 8.1 | — | Sep 24, 2026 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers t... |
| CVE-2026-93291 | CRITICAL | 9.4 | — | Sep 24, 2026 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which c... |
| CVE-2026-93290 | MEDIUM | 5.5 | — | Sep 24, 2026 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access i... |
| CVE-2026-93289 | HIGH | 7.5 | — | Sep 24, 2026 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now