2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90680 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of... |
| CVE-2026-90608 | CRITICAL | 9.9 | 0.8% | Sep 14, 2026 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file... |
| CVE-2026-90607 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file... |
| CVE-2026-90606 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIp... |
| CVE-2026-90605 | CRITICAL | 9.9 | 0.5% | Sep 14, 2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter... |
| CVE-2026-81648 | CRITICAL | 10 | 0.3% | Sep 13, 2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX ... |
| CVE-2026-90558 | CRITICAL | 9.8 | 0.5% | Sep 12, 2026 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val... |
| CVE-2026-78159 | CRITICAL | 9.8 | 0.8% | Sep 12, 2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including... |
| CVE-2026-78006 | CRITICAL | 9.8 | 0.8% | Sep 12, 2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including... |
| CVE-2026-85681 | CRITICAL | 9.8 | 0.3% | Sep 12, 2026 | The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it ma... |
| CVE-2026-84171 | CRITICAL | 9.8 | 0.4% | Sep 12, 2026 | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before... |
| CVE-2026-82845 | CRITICAL | 9.9 | 0.4% | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deser... |
| CVE-2026-81402 | CRITICAL | 9.8 | 0.4% | Sep 12, 2026 | The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type v... |
| CVE-2026-77006 | CRITICAL | 9.6 | 0.2% | Sep 12, 2026 | The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capab... |
| CVE-2026-77005 | CRITICAL | 9.6 | 0.3% | Sep 12, 2026 | The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a... |
| CVE-2026-75800 | CRITICAL | 9.8 | 0.4% | Sep 12, 2026 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication resp... |
| CVE-2026-87719 | CRITICAL | 9.9 | 0.6% | Sep 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 b... |
| CVE-2026-85706 | CRITICAL | 10 | 9.3% | Sep 12, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.... |
| CVE-2026-90456 | CRITICAL | 9.2 | 0.3% | Sep 11, 2026 | An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-know... |
| CVE-2026-89713 | CRITICAL | 9.1 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock n... |
| CVE-2026-89712 | CRITICAL | 9.8 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping... |
| CVE-2026-89708 | CRITICAL | 9.8 | 0.4% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-fr... |
| CVE-2026-89703 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_sti... |
| CVE-2026-89702 | CRITICAL | 9.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_lo... |
| CVE-2026-89697 | CRITICAL | 9.1 | 0.6% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATT... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now