2026 CVE Vulnerabilities

44,078 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-30120CRITICAL9.8remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2026-9862CRITICAL9.8Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd...
CVE-2026-52704CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a...
CVE-2026-5482CRITICAL9.3Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restrictio...
CVE-2026-49757CRITICAL9.2Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users...
CVE-2026-8935CRITICAL9.8The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that i...
CVE-2026-11526CRITICAL9.8GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments ...
CVE-2026-12183CRITICAL9.8Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentic...
CVE-2026-11624CRITICAL9.4The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne...
CVE-2026-53838CRITICAL9.8OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes ...
CVE-2026-53609CRITICAL9.1ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se...
CVE-2026-53519CRITICAL9.1Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13,...
CVE-2026-46716CRITICAL9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be...
CVE-2026-41157CRITICAL9.8A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound ...
CVE-2026-44990CRITICAL9.3ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi...
CVE-2026-53407CRITICAL9.8Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7....
CVE-2026-50101CRITICAL9.2Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each...
CVE-2026-28742CRITICAL9.8Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar...
CVE-2026-48558CRITICAL10SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the ...
CVE-2026-44172CRITICAL9.1MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taki...
CVE-2026-44170CRITICAL9.8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-50086CRITICAL9.8The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke...
CVE-2026-50085CRITICAL9.8The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ...
CVE-2026-50083CRITICAL9.8The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-...
CVE-2026-47691CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now