2026 CVE Vulnerabilities
67,335 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57225 | MEDIUM | 5.5 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-57223 | HIGH | 7 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-93873 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to... |
| CVE-2026-93872 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comment... |
| CVE-2026-93871 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticate... |
| CVE-2026-93870 | MEDIUM | 4.3 | 0.1% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge... |
| CVE-2026-93869 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de... |
| CVE-2026-93868 | HIGH | 8.1 | 0.6% | Sep 18, 2026 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creati... |
| CVE-2026-93841 | MEDIUM | 5.3 | — | Sep 18, 2026 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind... |
| CVE-2026-93840 | MEDIUM | 5.3 | — | Sep 18, 2026 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in Sampling... |
| CVE-2026-93839 | CRITICAL | 9.8 | 0.6% | Sep 18, 2026 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow... |
| CVE-2026-93838 | MEDIUM | 5.9 | 0.5% | Sep 18, 2026 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails t... |
| CVE-2026-93031 | HIGH | 8.8 | 0.6% | Sep 18, 2026 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable ... |
| CVE-2026-92708 | HIGH | 7.5 | 0.3% | Sep 18, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-91205 | MEDIUM | 6 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation ... |
| CVE-2026-91203 | MEDIUM | 6 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a syml... |
| CVE-2026-91202 | MEDIUM | 6.1 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory co... |
| CVE-2026-84241 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authoriz... |
| CVE-2026-84239 | HIGH | 7.6 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to imp... |
| CVE-2026-84108 | HIGH | 8.1 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization... |
| CVE-2026-84106 | HIGH | 8.9 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ... |
| CVE-2026-84105 | HIGH | 7.7 | 0.4% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to imp... |
| CVE-2026-84089 | HIGH | 7.8 | 0.1% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege man... |
| CVE-2026-84086 | HIGH | 7.2 | 0.7% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ... |
| CVE-2026-84085 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutral... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now