2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84325 | CRITICAL | 9.8 | 0.2% | Sep 2, 2026 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging s... |
| CVE-2026-84324 | CRITICAL | 9 | 0.3% | Sep 2, 2026 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outs... |
| CVE-2026-84480 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to ... |
| CVE-2026-84479 | CRITICAL | 9.1 | 0.3% | Sep 1, 2026 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplie... |
| CVE-2026-84639 | CRITICAL | 9.1 | 0.3% | Sep 1, 2026 | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was... |
| CVE-2026-84637 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, ... |
| CVE-2026-84372 | CRITICAL | 9.8 | 0.4% | Sep 1, 2026 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, p... |
| CVE-2026-83548 | CRITICAL | 10 | 0.3% | Sep 1, 2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern... |
| CVE-2026-75604 | CRITICAL | 9 | 1.1% | Sep 1, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js app... |
| CVE-2026-73778 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An una... |
| CVE-2026-73749 | CRITICAL | 9.8 | 0.5% | Sep 1, 2026 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unaut... |
| CVE-2026-76658 | CRITICAL | 10 | 0.4% | Sep 1, 2026 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthentica... |
| CVE-2026-76657 | CRITICAL | 10 | 0.4% | Sep 1, 2026 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauth... |
| CVE-2026-73701 | CRITICAL | 9 | 0.5% | Sep 1, 2026 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabri... |
| CVE-2026-73700 | CRITICAL | 9 | 0.3% | Sep 1, 2026 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low... |
| CVE-2026-19766 | CRITICAL | 9.6 | 0.3% | Sep 1, 2026 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Succ... |
| CVE-2026-52111 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration ... |
| CVE-2026-19593 | CRITICAL | 9.8 | 0.1% | Sep 1, 2026 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user open... |
| CVE-2026-51934 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote at... |
| CVE-2026-79687 | CRITICAL | 9 | — | Sep 1, 2026 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker... |
| CVE-2026-51770 | CRITICAL | 9.8 | 0.2% | Sep 1, 2026 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat... |
| CVE-2026-51769 | CRITICAL | 9.8 | 0.2% | Sep 1, 2026 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica... |
| CVE-2026-51767 | CRITICAL | 9.8 | 0.2% | Sep 1, 2026 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
| CVE-2026-18931 | CRITICAL | 9.1 | — | Sep 1, 2026 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management S... |
| CVE-2026-78012 | CRITICAL | 9.8 | 0.5% | Sep 1, 2026 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now