2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94084 | CRITICAL | 9.4 | 0.4% | Sep 20, 2026 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r... |
| CVE-2026-94083 | CRITICAL | 9.4 | 0.4% | Sep 20, 2026 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state... |
| CVE-2026-93958 | CRITICAL | 9.1 | 2.2% | Sep 20, 2026 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/... |
| CVE-2026-93985 | CRITICAL | 9.9 | 0.5% | Sep 19, 2026 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template ... |
| CVE-2026-78030 | CRITICAL | 9.8 | 0.7% | Sep 19, 2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.... |
| CVE-2026-93742 | CRITICAL | 9.9 | 1.9% | Sep 19, 2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of ... |
| CVE-2026-86591 | CRITICAL | 9.8 | 0.4% | Sep 19, 2026 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowi... |
| CVE-2026-93741 | CRITICAL | 10 | 0.6% | Sep 19, 2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the functio... |
| CVE-2026-92229 | CRITICAL | 9.1 | 0.4% | Sep 19, 2026 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitr... |
| CVE-2026-89274 | CRITICAL | 9.1 | 0.4% | Sep 19, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu... |
| CVE-2026-84434 | CRITICAL | 9.8 | 0.7% | Sep 19, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.... |
| CVE-2026-93740 | CRITICAL | 10 | 0.6% | Sep 18, 2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file... |
| CVE-2026-93739 | CRITICAL | 9.9 | 0.5% | Sep 18, 2026 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /bo... |
| CVE-2026-75885 | CRITICAL | 9.3 | 0.4% | Sep 18, 2026 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` end... |
| CVE-2026-93738 | CRITICAL | 9.9 | 0.5% | Sep 18, 2026 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boa... |
| CVE-2026-93839 | CRITICAL | 9.8 | 0.6% | Sep 18, 2026 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow... |
| CVE-2026-84082 | CRITICAL | 9.8 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutra... |
| CVE-2026-84078 | CRITICAL | 9.9 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An... |
| CVE-2026-84075 | CRITICAL | 9.9 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentic... |
| CVE-2026-84073 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to i... |
| CVE-2026-84064 | CRITICAL | 9.9 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to i... |
| CVE-2026-84031 | CRITICAL | 9 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ... |
| CVE-2026-82967 | CRITICAL | 9.8 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attack... |
| CVE-2026-82832 | CRITICAL | 9.6 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ... |
| CVE-2026-82340 | CRITICAL | 9.8 | 0.5% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled refl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now