2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76174 | CRITICAL | 9.4 | 0.5% | Sep 3, 2026 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The a... |
| CVE-2026-19117 | CRITICAL | 9.8 | 0.3% | Sep 2, 2026 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and... |
| CVE-2026-66786 | CRITICAL | 9.1 | 0.7% | Sep 2, 2026 | A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from th... |
| CVE-2026-53671 | CRITICAL | 9.3 | 0.3% | Sep 2, 2026 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstra... |
| CVE-2026-53670 | CRITICAL | 9.3 | 0.3% | Sep 2, 2026 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Pre... |
| CVE-2026-53649 | CRITICAL | 9.6 | 0.2% | Sep 2, 2026 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1... |
| CVE-2026-20279 | CRITICAL | 9.8 | 0.3% | Sep 2, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t... |
| CVE-2026-20274 | CRITICAL | 9.8 | 0.7% | Sep 2, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t... |
| CVE-2026-20212 | CRITICAL | 9.8 | — | Sep 2, 2026 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remo... |
| CVE-2026-53611 | CRITICAL | 9.8 | 1.0% | Sep 2, 2026 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet... |
| CVE-2026-82955 | CRITICAL | 9 | 0.1% | Sep 2, 2026 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance in... |
| CVE-2026-77009 | CRITICAL | 9.9 | 0.3% | Sep 2, 2026 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user... |
| CVE-2026-4357 | CRITICAL | 10 | 0.3% | Sep 2, 2026 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as wel... |
| CVE-2026-73475 | CRITICAL | 9.1 | 0.2% | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce Pa... |
| CVE-2026-84803 | CRITICAL | 9 | — | Sep 2, 2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extensio... |
| CVE-2026-84795 | CRITICAL | 9.8 | — | Sep 2, 2026 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactiva... |
| CVE-2026-81294 | CRITICAL | 9.8 | — | Sep 2, 2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. |
| CVE-2026-81286 | CRITICAL | 9.3 | 0.3% | Sep 2, 2026 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. |
| CVE-2026-78657 | CRITICAL | 9.8 | — | Sep 2, 2026 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien... |
| CVE-2026-9055 | CRITICAL | 9.8 | — | Sep 2, 2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-84699 | CRITICAL | 9.1 | 0.4% | Sep 2, 2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset... |
| CVE-2026-84354 | CRITICAL | 9.6 | 0.2% | Sep 2, 2026 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging socia... |
| CVE-2026-84353 | CRITICAL | 9.6 | 0.3% | Sep 2, 2026 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leve... |
| CVE-2026-84352 | CRITICAL | 9.6 | 0.3% | Sep 2, 2026 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbit... |
| CVE-2026-84333 | CRITICAL | 9.6 | 0.2% | Sep 2, 2026 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now