2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79391 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP por... |
| CVE-2026-71625 | CRITICAL | 9.8 | 0.2% | Sep 4, 2026 | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController... |
| CVE-2026-71624 | CRITICAL | 9.8 | 0.5% | Sep 4, 2026 | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class... |
| CVE-2026-81939 | CRITICAL | 9.1 | 0.7% | Sep 4, 2026 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing func... |
| CVE-2026-78328 | CRITICAL | 9.1 | 0.5% | Sep 4, 2026 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allow... |
| CVE-2026-78327 | CRITICAL | 9.1 | 1.6% | Sep 4, 2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the Sonic... |
| CVE-2026-57163 | CRITICAL | 9.1 | 0.3% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer o... |
| CVE-2026-57162 | CRITICAL | 9.1 | 0.4% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer o... |
| CVE-2026-84961 | CRITICAL | 9.1 | 0.1% | Sep 4, 2026 | undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and re... |
| CVE-2026-78745 | CRITICAL | 9.8 | 0.7% | Sep 4, 2026 | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via ... |
| CVE-2026-75430 | CRITICAL | 9.8 | 0.9% | Sep 4, 2026 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without au... |
| CVE-2026-31020 | CRITICAL | 9.8 | 0.6% | Sep 4, 2026 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content... |
| CVE-2026-18221 | CRITICAL | 9.8 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of cli... |
| CVE-2026-17207 | CRITICAL | 9.1 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to ... |
| CVE-2026-17057 | CRITICAL | 9.1 | 0.4% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to... |
| CVE-2026-77822 | CRITICAL | 9.6 | 0.2% | Sep 4, 2026 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-s... |
| CVE-2026-75431 | CRITICAL | 9.1 | 0.8% | Sep 4, 2026 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. Th... |
| CVE-2026-75429 | CRITICAL | 9.8 | 0.6% | Sep 4, 2026 | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/proces... |
| CVE-2026-75171 | CRITICAL | 9.8 | 0.2% | Sep 4, 2026 | An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling c... |
| CVE-2026-75160 | CRITICAL | 9.1 | 0.4% | Sep 4, 2026 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin... |
| CVE-2026-44402 | CRITICAL | 9.8 | 0.9% | Sep 4, 2026 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmw... |
| CVE-2026-19274 | CRITICAL | 9.6 | 0.2% | Sep 4, 2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authentic... |
| CVE-2026-18658 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to S... |
| CVE-2026-85696 | CRITICAL | 9.8 | 1.5% | Sep 4, 2026 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are ... |
| CVE-2026-85695 | CRITICAL | 9.4 | 0.4% | Sep 4, 2026 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now