2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6853CRITICAL9.8Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ...
CVE-2026-54133CRITICAL9.8jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc...
CVE-2026-53787CRITICAL9.8Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili...
CVE-2026-47210CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi...
CVE-2026-47208CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-47140CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ...
CVE-2026-47137CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ...
CVE-2026-47131CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__...
CVE-2026-45674CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-10557CRITICAL9.8The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and a...
CVE-2026-11849CRITICAL9.8The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una...
CVE-2026-50628CRITICAL9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all...
CVE-2026-50627CRITICAL9.1The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok...
CVE-2026-49875CRITICAL9.8Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary...
CVE-2026-11535CRITICAL9.4An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut...
CVE-2026-48611CRITICAL9.8Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or ...
CVE-2026-47370CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47369CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47367CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-47365CRITICAL9.9Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated...
CVE-2026-45060CRITICAL9.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php en...
CVE-2026-42846CRITICAL9.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature ...
CVE-2026-49060CRITICAL9.8Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This iss...
CVE-2026-42647CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport ...
CVE-2026-39494CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now