CVEs from 2026

14,112 normalized CVEs published or assigned in this year.

Total
14,112
critical
critical 1,245
high
high 4,691
medium
medium 4,468
low
low 488
% Critical
8.8%
% with KEV
0.4%
% with exploit
0.8%

Top vendors

Top products

  • chrome 522
  • firepower_threat_defense_software 300
  • firepower_threat_defense 298
  • gcp 247
  • openclaw 172
  • commerce 104
  • netweaver_application_server_abap 102
  • commerce_b2b 89
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-48027 critical 9.8 10.0 7d ago Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvest…
CVE-2026-45247 critical 9.8 10.0 9d ago Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying …
CVE-2026-48172 critical 9.8 10.0 14d ago LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with ro…
CVE-2026-9082 critical 9.8 10.0 14d ago Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-8398 critical 9.8 10.0 20d ago Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2026-20182 critical 10.0 10.0 20d ago Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges…
CVE-2026-0257 critical 9.1 10.0 21d ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2026-45321 critical 9.6 10.0 23d ago TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CVE-2026-42208 critical 9.8 10.0 27d ago BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cr…
CVE-2026-0300 critical 9.8 10.0 28d ago Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitra…
CVE-2026-41940 critical 9.8 10.0 1mo ago WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized a…
CVE-2026-33017 critical 9.8 10.0 3mo ago Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CVE-2026-24858 critical 9.8 10.0 4mo ago Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a register…