2026 CVE Vulnerabilities

64,734 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-94084CRITICAL9.4Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r...
CVE-2026-94083CRITICAL9.4Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state...
CVE-2026-93958CRITICAL9.1A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/...
CVE-2026-93985CRITICAL9.9OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template ...
CVE-2026-78030CRITICAL9.8DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM....
CVE-2026-93742CRITICAL9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of ...
CVE-2026-86591CRITICAL9.8The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowi...
CVE-2026-93741CRITICAL10A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the functio...
CVE-2026-92229CRITICAL9.1The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitr...
CVE-2026-89274CRITICAL9.1The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu...
CVE-2026-84434CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1....
CVE-2026-93740CRITICAL10A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file...
CVE-2026-93739CRITICAL9.9A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /bo...
CVE-2026-75885CRITICAL9.3A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` end...
CVE-2026-93738CRITICAL9.9A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boa...
CVE-2026-93839CRITICAL9.8LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow...
CVE-2026-84082CRITICAL9.8IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutra...
CVE-2026-84078CRITICAL9.9IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An...
CVE-2026-84075CRITICAL9.9IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentic...
CVE-2026-84073CRITICAL9.1IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to i...
CVE-2026-84064CRITICAL9.9IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to i...
CVE-2026-84031CRITICAL9IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ...
CVE-2026-82967CRITICAL9.8IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attack...
CVE-2026-82832CRITICAL9.6IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ...
CVE-2026-82340CRITICAL9.8IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled refl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now