2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51747 | CRITICAL | 9.8 | 0.2% | Sep 1, 2026 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51744 | CRITICAL | 9.8 | 0.4% | Sep 1, 2026 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated... |
| CVE-2026-51743 | CRITICAL | 9.1 | — | Sep 1, 2026 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
| CVE-2026-51741 | CRITICAL | 9.8 | 0.2% | Sep 1, 2026 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a... |
| CVE-2026-18765 | CRITICAL | 9.8 | — | Sep 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software ... |
| CVE-2026-84200 | CRITICAL | 9 | 0.2% | Sep 1, 2026 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combi... |
| CVE-2026-18550 | CRITICAL | 9.8 | 0.3% | Sep 1, 2026 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all ve... |
| CVE-2026-4813 | CRITICAL | 9.4 | — | Sep 1, 2026 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administ... |
| CVE-2026-78319 | CRITICAL | 9.3 | 0.4% | Sep 1, 2026 | A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An un... |
| CVE-2026-83772 | CRITICAL | 9.9 | 1.7% | Sep 1, 2026 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the ... |
| CVE-2026-75865 | CRITICAL | 9.8 | 0.5% | Sep 1, 2026 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress i... |
| CVE-2026-67394 | CRITICAL | 9 | 1.2% | Sep 1, 2026 | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, aff... |
| CVE-2026-83524 | CRITICAL | 9.9 | 1.7% | Aug 31, 2026 | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 2... |
| CVE-2026-82971 | CRITICAL | 10 | 1.9% | Aug 31, 2026 | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-b... |
| CVE-2026-82954 | CRITICAL | 9.9 | 0.6% | Aug 31, 2026 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the fi... |
| CVE-2026-82226 | CRITICAL | 9.8 | 0.3% | Aug 31, 2026 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. |
| CVE-2026-81780 | CRITICAL | 10 | 0.3% | Aug 31, 2026 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. |
| CVE-2026-81779 | CRITICAL | 10 | 0.3% | Aug 31, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software I... |
| CVE-2026-81763 | CRITICAL | 9.3 | 0.2% | Aug 31, 2026 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. |
| CVE-2026-81756 | CRITICAL | 9.3 | 0.3% | Aug 31, 2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. |
| CVE-2026-81293 | CRITICAL | 9.3 | 0.2% | Aug 31, 2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. |
| CVE-2026-79408 | CRITICAL | 9.8 | 0.5% | Aug 31, 2026 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path arg... |
| CVE-2026-38577 | CRITICAL | 9.8 | 0.1% | Aug 31, 2026 | Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. |
| CVE-2026-51740 | CRITICAL | 9.8 | — | Aug 31, 2026 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacke... |
| CVE-2026-51738 | CRITICAL | 9.8 | 0.2% | Aug 31, 2026 | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now