2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82616 | CRITICAL | 9.9 | 0.6% | Aug 31, 2026 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the fi... |
| CVE-2026-82593 | CRITICAL | 9.9 | 0.5% | Aug 31, 2026 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgr... |
| CVE-2026-82592 | CRITICAL | 9.9 | 0.8% | Aug 30, 2026 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDisk... |
| CVE-2026-82542 | CRITICAL | 10 | 0.6% | Aug 30, 2026 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the fi... |
| CVE-2026-82539 | CRITICAL | 9.1 | 0.6% | Aug 30, 2026 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of t... |
| CVE-2026-15980 | CRITICAL | 9.8 | 0.5% | Aug 30, 2026 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.... |
| CVE-2026-15369 | CRITICAL | 9.8 | 0.4% | Aug 29, 2026 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versio... |
| CVE-2026-82460 | CRITICAL | 9.8 | 1.2% | Aug 29, 2026 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint... |
| CVE-2026-82456 | CRITICAL | 10 | 1.4% | Aug 29, 2026 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c... |
| CVE-2026-82454 | CRITICAL | 9.1 | 0.4% | Aug 29, 2026 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in toke... |
| CVE-2026-82452 | CRITICAL | 9.8 | 0.5% | Aug 29, 2026 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lac... |
| CVE-2026-82448 | CRITICAL | 9.8 | 0.4% | Aug 29, 2026 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated... |
| CVE-2026-14494 | CRITICAL | 9.8 | 0.7% | Aug 29, 2026 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.... |
| CVE-2026-80725 | CRITICAL | 9.8 | 0.2% | Aug 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation cri... |
| CVE-2026-77012 | CRITICAL | 9.3 | 0.2% | Aug 29, 2026 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated end... |
| CVE-2026-16947 | CRITICAL | 9.1 | 0.2% | Aug 29, 2026 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path b... |
| CVE-2026-16259 | CRITICAL | 9.8 | 0.3% | Aug 29, 2026 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthentic... |
| CVE-2026-10522 | CRITICAL | 9.8 | 0.1% | Aug 29, 2026 | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend ... |
| CVE-2026-51663 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
| CVE-2026-51661 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated... |
| CVE-2026-3627 | CRITICAL | 9.1 | 0.5% | Aug 28, 2026 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state... |
| CVE-2026-19295 | CRITICAL | 9.9 | 1.0% | Aug 28, 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in... |
| CVE-2026-19286 | CRITICAL | 9.8 | 0.6% | Aug 28, 2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcemen... |
| CVE-2026-18527 | CRITICAL | 9.9 | 0.3% | Aug 28, 2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker t... |
| CVE-2026-82329 | CRITICAL | 9.8 | 1.2% | Aug 28, 2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now