2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-82616CRITICAL9.9A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the fi...
CVE-2026-82593CRITICAL9.9A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgr...
CVE-2026-82592CRITICAL9.9A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDisk...
CVE-2026-82542CRITICAL10A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the fi...
CVE-2026-82539CRITICAL9.1A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of t...
CVE-2026-15980CRITICAL9.8The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5....
CVE-2026-15369CRITICAL9.8The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versio...
CVE-2026-82460CRITICAL9.8Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint...
CVE-2026-82456CRITICAL10argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c...
CVE-2026-82454CRITICAL9.1The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in toke...
CVE-2026-82452CRITICAL9.8rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lac...
CVE-2026-82448CRITICAL9.8Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated...
CVE-2026-14494CRITICAL9.8The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1....
CVE-2026-80725CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation cri...
CVE-2026-77012CRITICAL9.3The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated end...
CVE-2026-16947CRITICAL9.1The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path b...
CVE-2026-16259CRITICAL9.8The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthentic...
CVE-2026-10522CRITICAL9.8The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend ...
CVE-2026-51663CRITICAL9.8Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at...
CVE-2026-51661CRITICAL9.1Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated...
CVE-2026-3627CRITICAL9.1IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state...
CVE-2026-19295CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in...
CVE-2026-19286CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcemen...
CVE-2026-18527CRITICAL9.9IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker t...
CVE-2026-82329CRITICAL9.8JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now