2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-93228CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 ...
CVE-2026-93207CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decod...
CVE-2026-97404CRITICAL9.2In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty...
CVE-2026-90481CRITICAL9.2In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occu...
CVE-2026-88351CRITICAL9.8An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specia...
CVE-2026-81549CRITICAL9.6IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-51994CRITICAL9.1mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata...
CVE-2026-97360CRITICAL10HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticat...
CVE-2026-97359CRITICAL10HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows u...
CVE-2026-91187CRITICAL9.3Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote at...
CVE-2026-19072CRITICAL9.9Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each e...
CVE-2026-12227CRITICAL9.8The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2026-78312CRITICAL9.1Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78308CRITICAL9.8Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before...
CVE-2026-96891CRITICAL9.8A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel....
CVE-2026-18467CRITICAL9.8The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions...
CVE-2026-93577CRITICAL9.9GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1...
CVE-2026-89078CRITICAL9.9GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1...
CVE-2026-93352CRITICAL9.8Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absen...
CVE-2026-6928CRITICAL9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can i...
CVE-2026-6730CRITICAL9.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user cou...
CVE-2026-6721CRITICAL9.8IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is inc...
CVE-2026-67404CRITICAL9.2RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bu...
CVE-2026-67231CRITICAL9.1RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-sto...
CVE-2026-87900CRITICAL9.4Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now