2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54181 | MEDIUM | 5.4 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54177 | MEDIUM | 6.6 | 0.7% | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54176 | MEDIUM | 6.5 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54150 | MEDIUM | 6.9 | — | Sep 14, 2026 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-vide... |
| CVE-2026-53495 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the ... |
| CVE-2026-50157 | MEDIUM | 6.5 | — | Sep 14, 2026 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorize... |
| CVE-2026-47256 | MEDIUM | 5.3 | 0.4% | Sep 14, 2026 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating... |
| CVE-2026-19542 | MEDIUM | 5.6 | 0.3% | Sep 14, 2026 | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end ... |
| CVE-2026-90804 | MEDIUM | 6.1 | 0.1% | Sep 14, 2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_fram... |
| CVE-2026-90803 | MEDIUM | 6.8 | 0.1% | Sep 14, 2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_... |
| CVE-2026-90802 | MEDIUM | 4.4 | 0.1% | Sep 14, 2026 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the... |
| CVE-2026-90801 | MEDIUM | 6.6 | 0.1% | Sep 14, 2026 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c... |
| CVE-2026-90796 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file... |
| CVE-2026-57497 | MEDIUM | 5.3 | — | Sep 14, 2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in sessio... |
| CVE-2026-55837 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_... |
| CVE-2026-55102 | MEDIUM | 5.8 | — | Sep 14, 2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src... |
| CVE-2026-55073 | MEDIUM | 6.2 | 0.2% | Sep 14, 2026 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restri... |
| CVE-2026-54452 | MEDIUM | 6.3 | 0.4% | Sep 14, 2026 | safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the... |
| CVE-2026-53496 | MEDIUM | 5.3 | — | Sep 14, 2026 | ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL... |
| CVE-2026-15923 | MEDIUM | 4.6 | — | Sep 14, 2026 | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O l... |
| CVE-2026-90996 | MEDIUM | 4 | 0.1% | Sep 14, 2026 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to th... |
| CVE-2026-90995 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Plug... |
| CVE-2026-90994 | MEDIUM | 4 | 0.1% | Sep 14, 2026 | A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser,... |
| CVE-2026-90795 | MEDIUM | 4.3 | — | Sep 14, 2026 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function o... |
| CVE-2026-90794 | MEDIUM | 6.3 | — | Sep 14, 2026 | A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file sce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now