2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-50883CRITICAL9.6An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute ...
CVE-2026-50880CRITICAL9.8An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod...
CVE-2026-50873CRITICAL9.8An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec...
CVE-2026-50872CRITICAL9.8An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra...
CVE-2026-50871CRITICAL9.8An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc...
CVE-2026-50869CRITICAL9.8An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi...
CVE-2026-49952CRITICAL9.3Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-48114CRITICAL9.8Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab...
CVE-2026-45390CRITICAL9.1In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire...
CVE-2026-45388CRITICAL9.1In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,...
CVE-2026-39196CRITICAL9.8Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th...
CVE-2026-39006CRITICAL9.8An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component...
CVE-2026-38812CRITICAL9.8RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio...
CVE-2026-38329CRITICAL9.8Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi...
CVE-2026-38065CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ...
CVE-2026-38064CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu...
CVE-2026-38063CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via...
CVE-2026-38062CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat...
CVE-2026-38061CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum...
CVE-2026-38060CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p...
CVE-2026-36537CRITICAL9.8ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The applica...
CVE-2026-30121CRITICAL9.1remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
CVE-2026-30120CRITICAL9.8remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2026-9862CRITICAL9.8Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd...
CVE-2026-52704CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now