2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93228 | CRITICAL | 9.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 ... |
| CVE-2026-93207 | CRITICAL | 9.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decod... |
| CVE-2026-97404 | CRITICAL | 9.2 | 0.3% | Sep 24, 2026 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty... |
| CVE-2026-90481 | CRITICAL | 9.2 | — | Sep 24, 2026 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occu... |
| CVE-2026-88351 | CRITICAL | 9.8 | 0.1% | Sep 24, 2026 | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specia... |
| CVE-2026-81549 | CRITICAL | 9.6 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-51994 | CRITICAL | 9.1 | 0.2% | Sep 24, 2026 | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata... |
| CVE-2026-97360 | CRITICAL | 10 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticat... |
| CVE-2026-97359 | CRITICAL | 10 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows u... |
| CVE-2026-91187 | CRITICAL | 9.3 | — | Sep 24, 2026 | Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote at... |
| CVE-2026-19072 | CRITICAL | 9.9 | — | Sep 24, 2026 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each e... |
| CVE-2026-12227 | CRITICAL | 9.8 | 0.8% | Sep 24, 2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an... |
| CVE-2026-78312 | CRITICAL | 9.1 | 0.3% | Sep 24, 2026 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78308 | CRITICAL | 9.8 | 0.3% | Sep 24, 2026 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before... |
| CVE-2026-96891 | CRITICAL | 9.8 | 0.7% | Sep 24, 2026 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.... |
| CVE-2026-18467 | CRITICAL | 9.8 | 0.4% | Sep 24, 2026 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions... |
| CVE-2026-93577 | CRITICAL | 9.9 | 0.4% | Sep 24, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1... |
| CVE-2026-89078 | CRITICAL | 9.9 | 0.4% | Sep 24, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1... |
| CVE-2026-93352 | CRITICAL | 9.8 | 0.6% | Sep 23, 2026 | Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absen... |
| CVE-2026-6928 | CRITICAL | 9.8 | 0.4% | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can i... |
| CVE-2026-6730 | CRITICAL | 9.8 | 0.4% | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user cou... |
| CVE-2026-6721 | CRITICAL | 9.8 | 1.4% | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is inc... |
| CVE-2026-67404 | CRITICAL | 9.2 | 0.2% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bu... |
| CVE-2026-67231 | CRITICAL | 9.1 | 0.2% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-sto... |
| CVE-2026-87900 | CRITICAL | 9.4 | 0.6% | Sep 23, 2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now