2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-51622CRITICAL9.1Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers...
CVE-2026-51611CRITICAL9.8Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at...
CVE-2026-82078CRITICAL9.1An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG...
CVE-2026-81578CRITICAL9.8An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under sp...
CVE-2026-37751CRITICAL9.8An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v...
CVE-2026-37236CRITICAL9.8grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override hea...
CVE-2026-82244CRITICAL9.1Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticat...
CVE-2026-82222CRITICAL10Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af...
CVE-2026-42007CRITICAL9.1An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free ...
CVE-2026-18918CRITICAL9.1In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supp...
CVE-2026-80714CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced co...
CVE-2026-80694CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_...
CVE-2026-80693CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to the a...
CVE-2026-80684CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV alloca...
CVE-2026-80681CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit...
CVE-2026-80674CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden ...
CVE-2026-80673CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ...
CVE-2026-80671CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, an...
CVE-2026-80670CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in mac...
CVE-2026-80668CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to...
CVE-2026-80634CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on...
CVE-2026-80630CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_red...
CVE-2026-80617CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size fo...
CVE-2026-80612CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsu...
CVE-2026-80609CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now