2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-80603CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by...
CVE-2026-80600CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s...
CVE-2026-78032CRITICAL9.3SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with...
CVE-2026-76581CRITICAL9.8The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2026-40541CRITICAL9An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain ...
CVE-2026-82090CRITICAL9.2Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alt...
CVE-2026-82082CRITICAL9.8NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje...
CVE-2026-78174CRITICAL9.3WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-priv...
CVE-2026-61800CRITICAL9.1Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I...
CVE-2026-19318CRITICAL9.3A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated a...
CVE-2026-19315CRITICAL9.3A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to...
CVE-2026-19313CRITICAL9.3An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to ex...
CVE-2026-13086CRITICAL9.3A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security fe...
CVE-2026-78239CRITICAL9.8Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at...
CVE-2026-76943CRITICAL9.8Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp...
CVE-2026-76179CRITICAL9.8An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication ...
CVE-2026-75337CRITICAL9.8The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us...
CVE-2026-73125CRITICAL9.8Ebyte device web management interface does not consistently enforce authentication before granting access to administra...
CVE-2026-71187CRITICAL9.8The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke...
CVE-2026-69658CRITICAL9.8MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta...
CVE-2026-68929CRITICAL9.3FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th...
CVE-2026-50152CRITICAL9.1Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2...
CVE-2026-74820CRITICAL10ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne...
CVE-2026-6876CRITICAL10ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This securi...
CVE-2026-59313CRITICAL9.8Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now