2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-90680CRITICAL9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of...
CVE-2026-90608CRITICAL9.9A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file...
CVE-2026-90607CRITICAL9.9A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file...
CVE-2026-90606CRITICAL9.9A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIp...
CVE-2026-90605CRITICAL9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter...
CVE-2026-81648CRITICAL10The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX ...
CVE-2026-90558CRITICAL9.8sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val...
CVE-2026-78159CRITICAL9.8The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-78006CRITICAL9.8The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-85681CRITICAL9.8The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it ma...
CVE-2026-84171CRITICAL9.8The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before...
CVE-2026-82845CRITICAL9.9The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deser...
CVE-2026-81402CRITICAL9.8The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type v...
CVE-2026-77006CRITICAL9.6The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capab...
CVE-2026-77005CRITICAL9.6The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a...
CVE-2026-75800CRITICAL9.8The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication resp...
CVE-2026-87719CRITICAL9.9GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 b...
CVE-2026-85706CRITICAL10GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19....
CVE-2026-90456CRITICAL9.2An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-know...
CVE-2026-89713CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock n...
CVE-2026-89712CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping...
CVE-2026-89708CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-fr...
CVE-2026-89703CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_sti...
CVE-2026-89702CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_lo...
CVE-2026-89697CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now