2026 CVE Vulnerabilities

67,295 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63451MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-63450MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-63449MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-63448HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-63447HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-63446HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-61670MEDIUM6.5microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs s...
CVE-2026-57229MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57228CRITICAL9.1Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57227HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57225MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57223HIGH7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-93873MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to...
CVE-2026-93872HIGH7.5Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comment...
CVE-2026-93871MEDIUM5.4Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticate...
CVE-2026-93870MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge...
CVE-2026-93869MEDIUM6.1Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de...
CVE-2026-93868HIGH8.1Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creati...
CVE-2026-93841MEDIUM5.3vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind...
CVE-2026-93840MEDIUM5.3vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in Sampling...
CVE-2026-93839CRITICAL9.8LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow...
CVE-2026-93838MEDIUM5.9SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails t...
CVE-2026-93031HIGH8.8The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable ...
CVE-2026-92708HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-91205MEDIUM6A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now