2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-35268CRITICAL9.9Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that ar...
CVE-2026-35263CRITICAL9.9Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are...
CVE-2026-48777CRITICAL9.3FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1...
CVE-2026-22313CRITICAL9.1The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting a...
CVE-2026-0126CRITICAL9.8In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execu...
CVE-2026-53861CRITICAL9.8OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined...
CVE-2026-53776CRITICAL9.3Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by...
CVE-2026-12316CRITICAL9.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12315CRITICAL9.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund...
CVE-2026-12304CRITICAL9.1Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR...
CVE-2026-12297CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox...
CVE-2026-12296CRITICAL9.6Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 1...
CVE-2026-12295CRITICAL9.6Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefo...
CVE-2026-12294CRITICAL9.6Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox E...
CVE-2026-12293CRITICAL9.8Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-40750CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh...
CVE-2026-52715CRITICAL9.3Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
CVE-2026-49774CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc...
CVE-2026-49772CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell...
CVE-2026-39574CRITICAL9.3Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-9261CRITICAL9.8Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9260CRITICAL9.8Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9259CRITICAL9.8Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9258CRITICAL9.8Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-48853CRITICAL9.2Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now