2026 CVE Vulnerabilities

67,335 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57225MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57223HIGH7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-93873MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to...
CVE-2026-93872HIGH7.5Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comment...
CVE-2026-93871MEDIUM5.4Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticate...
CVE-2026-93870MEDIUM4.3Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge...
CVE-2026-93869MEDIUM6.1Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de...
CVE-2026-93868HIGH8.1Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creati...
CVE-2026-93841MEDIUM5.3vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind...
CVE-2026-93840MEDIUM5.3vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in Sampling...
CVE-2026-93839CRITICAL9.8LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow...
CVE-2026-93838MEDIUM5.9SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails t...
CVE-2026-93031HIGH8.8The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable ...
CVE-2026-92708HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-91205MEDIUM6A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation ...
CVE-2026-91203MEDIUM6A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a syml...
CVE-2026-91202MEDIUM6.1A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory co...
CVE-2026-84241HIGH8.1IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authoriz...
CVE-2026-84239HIGH7.6IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to imp...
CVE-2026-84108HIGH8.1IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization...
CVE-2026-84106HIGH8.9IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ...
CVE-2026-84105HIGH7.7IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to imp...
CVE-2026-84089HIGH7.8IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege man...
CVE-2026-84086HIGH7.2IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper ...
CVE-2026-84085HIGH8.1IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutral...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now