2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86167 | CRITICAL | 9.9 | 1.6% | Sep 6, 2026 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin... |
| CVE-2026-86165 | CRITICAL | 9.8 | 0.6% | Sep 6, 2026 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/... |
| CVE-2026-86218 | CRITICAL | 9.8 | 0.4% | Sep 6, 2026 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-75816 | CRITICAL | 9.8 | 0.5% | Sep 6, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all ... |
| CVE-2026-16310 | CRITICAL | 9.8 | 0.3% | Sep 6, 2026 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi... |
| CVE-2026-86153 | CRITICAL | 9.1 | 0.4% | Sep 6, 2026 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of th... |
| CVE-2026-86152 | CRITICAL | 10 | 1.9% | Sep 6, 2026 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the fil... |
| CVE-2026-86151 | CRITICAL | 9.1 | 2.0% | Sep 6, 2026 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/... |
| CVE-2026-86149 | CRITICAL | 9.1 | 2.0% | Sep 5, 2026 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetC... |
| CVE-2026-86148 | CRITICAL | 9.1 | 2.5% | Sep 5, 2026 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the f... |
| CVE-2026-86060 | CRITICAL | 9.8 | 0.4% | Sep 5, 2026 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited chara... |
| CVE-2026-67278 | CRITICAL | 9.1 | 0.3% | Sep 5, 2026 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificat... |
| CVE-2026-86190 | CRITICAL | 9.1 | 0.3% | Sep 5, 2026 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user record... |
| CVE-2026-86189 | CRITICAL | 9.8 | 0.4% | Sep 5, 2026 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to w... |
| CVE-2026-86184 | CRITICAL | 9.8 | 0.6% | Sep 5, 2026 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows un... |
| CVE-2026-10196 | CRITICAL | 9.8 | 0.6% | Sep 5, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-86124 | CRITICAL | 9.8 | 1.0% | Sep 5, 2026 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces... |
| CVE-2026-86121 | CRITICAL | 9.8 | 1.1% | Sep 5, 2026 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and... |
| CVE-2026-78362 | CRITICAL | 9.8 | 0.3% | Sep 5, 2026 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its AP... |
| CVE-2026-83627 | CRITICAL | 9.8 | 0.8% | Sep 5, 2026 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code ... |
| CVE-2026-13447 | CRITICAL | 9.8 | 0.4% | Sep 5, 2026 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and includ... |
| CVE-2026-52777 | CRITICAL | 9.4 | 0.2% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerab... |
| CVE-2026-52766 | CRITICAL | 9.1 | 0.3% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseS... |
| CVE-2026-75925 | CRITICAL | 9.6 | 0.7% | Sep 4, 2026 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands... |
| CVE-2026-50894 | CRITICAL | 9.8 | 0.2% | Sep 4, 2026 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interfa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now