2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51622 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers... |
| CVE-2026-51611 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at... |
| CVE-2026-82078 | CRITICAL | 9.1 | 1.7% | Aug 28, 2026 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG... |
| CVE-2026-81578 | CRITICAL | 9.8 | 1.6% | Aug 28, 2026 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under sp... |
| CVE-2026-37751 | CRITICAL | 9.8 | 1.6% | Aug 28, 2026 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v... |
| CVE-2026-37236 | CRITICAL | 9.8 | 0.4% | Aug 28, 2026 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override hea... |
| CVE-2026-82244 | CRITICAL | 9.1 | — | Aug 28, 2026 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticat... |
| CVE-2026-82222 | CRITICAL | 10 | — | Aug 28, 2026 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af... |
| CVE-2026-42007 | CRITICAL | 9.1 | 0.3% | Aug 28, 2026 | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free ... |
| CVE-2026-18918 | CRITICAL | 9.1 | 0.4% | Aug 28, 2026 | In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supp... |
| CVE-2026-80714 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced co... |
| CVE-2026-80694 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_... |
| CVE-2026-80693 | CRITICAL | 9.3 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to the a... |
| CVE-2026-80684 | CRITICAL | 9.3 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV alloca... |
| CVE-2026-80681 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit... |
| CVE-2026-80674 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden ... |
| CVE-2026-80673 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ... |
| CVE-2026-80671 | CRITICAL | 9.3 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, an... |
| CVE-2026-80670 | CRITICAL | 9.1 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in mac... |
| CVE-2026-80668 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to... |
| CVE-2026-80634 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on... |
| CVE-2026-80630 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_red... |
| CVE-2026-80617 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size fo... |
| CVE-2026-80612 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsu... |
| CVE-2026-80609 | CRITICAL | 9.8 | 0.2% | Aug 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now