2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63374 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri... |
| CVE-2026-94127 | CRITICAL | 9.8 | 1.4% | Sep 22, 2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can ... |
| CVE-2026-93088 | CRITICAL | 9.8 | — | Sep 22, 2026 | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregat... |
| CVE-2026-84388 | CRITICAL | 9.6 | 0.4% | Sep 22, 2026 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versi... |
| CVE-2026-79313 | CRITICAL | 9.8 | — | Sep 22, 2026 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on perio... |
| CVE-2026-65113 | CRITICAL | 9.8 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded cred... |
| CVE-2026-95675 | CRITICAL | 9.8 | — | Sep 22, 2026 | D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that a... |
| CVE-2026-12718 | CRITICAL | 9.8 | — | Sep 22, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic I... |
| CVE-2026-93616 | CRITICAL | 9.8 | 2.4% | Sep 22, 2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary s... |
| CVE-2026-74849 | CRITICAL | 9.8 | — | Sep 22, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerabil... |
| CVE-2026-25254 | CRITICAL | 9.8 | 0.5% | Sep 22, 2026 | Improper authorization leads to Remote Code Execution via SocketIO interface. |
| CVE-2026-93556 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose passwor... |
| CVE-2026-89422 | CRITICAL | 9.3 | 0.4% | Sep 22, 2026 | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client c... |
| CVE-2026-93952 | CRITICAL | 10 | 0.7% | Sep 22, 2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile... |
| CVE-2026-87080 | CRITICAL | 9.1 | 0.1% | Sep 22, 2026 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never... |
| CVE-2026-87078 | CRITICAL | 9.1 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu... |
| CVE-2026-19658 | CRITICAL | 9.8 | 0.4% | Sep 22, 2026 | The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1... |
| CVE-2026-13355 | CRITICAL | 9.8 | 0.3% | Sep 22, 2026 | The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and incl... |
| CVE-2026-94493 | CRITICAL | 10 | 1.3% | Sep 22, 2026 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the... |
| CVE-2026-78847 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to ... |
| CVE-2026-94572 | CRITICAL | 9.4 | 0.5% | Sep 21, 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field... |
| CVE-2026-94571 | CRITICAL | 9.4 | 0.3% | Sep 21, 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redir... |
| CVE-2026-88405 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-funct... |
| CVE-2026-88404 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execut... |
| CVE-2026-88402 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now