2026 CVE Vulnerabilities

64,732 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-63374CRITICAL9.3AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri...
CVE-2026-94127CRITICAL9.8When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can ...
CVE-2026-93088CRITICAL9.8SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregat...
CVE-2026-84388CRITICAL9.6A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versi...
CVE-2026-79313CRITICAL9.8webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on perio...
CVE-2026-65113CRITICAL9.8NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded cred...
CVE-2026-95675CRITICAL9.8D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that a...
CVE-2026-12718CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic I...
CVE-2026-93616CRITICAL9.8A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary s...
CVE-2026-74849CRITICAL9.8Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerabil...
CVE-2026-25254CRITICAL9.8Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-93556CRITICAL9.3The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose passwor...
CVE-2026-89422CRITICAL9.3Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client c...
CVE-2026-93952CRITICAL10VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile...
CVE-2026-87080CRITICAL9.1Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never...
CVE-2026-87078CRITICAL9.1Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu...
CVE-2026-19658CRITICAL9.8The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1...
CVE-2026-13355CRITICAL9.8The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and incl...
CVE-2026-94493CRITICAL10A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the...
CVE-2026-78847CRITICAL9.8An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to ...
CVE-2026-94572CRITICAL9.4In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field...
CVE-2026-94571CRITICAL9.4In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redir...
CVE-2026-88405CRITICAL9.8A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-funct...
CVE-2026-88404CRITICAL9.8A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execut...
CVE-2026-88402CRITICAL9.8A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now