2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-51747CRITICAL9.8Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers...
CVE-2026-51744CRITICAL9.8Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated...
CVE-2026-51743CRITICAL9.1Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att...
CVE-2026-51741CRITICAL9.8Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a...
CVE-2026-18765CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software ...
CVE-2026-84200CRITICAL9Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combi...
CVE-2026-18550CRITICAL9.8The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all ve...
CVE-2026-4813CRITICAL9.4A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administ...
CVE-2026-78319CRITICAL9.3A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An un...
CVE-2026-83772CRITICAL9.9A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the ...
CVE-2026-75865CRITICAL9.8The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress i...
CVE-2026-67394CRITICAL9A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, aff...
CVE-2026-83524CRITICAL9.9A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 2...
CVE-2026-82971CRITICAL10A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-b...
CVE-2026-82954CRITICAL9.9A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the fi...
CVE-2026-82226CRITICAL9.8Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
CVE-2026-81780CRITICAL10Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-81779CRITICAL10Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software I...
CVE-2026-81763CRITICAL9.3Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
CVE-2026-81756CRITICAL9.3Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
CVE-2026-81293CRITICAL9.3Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-79408CRITICAL9.8An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path arg...
CVE-2026-38577CRITICAL9.8Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
CVE-2026-51740CRITICAL9.8Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacke...
CVE-2026-51738CRITICAL9.8Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now