2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12027CRITICAL9.6Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp...
CVE-2026-41005CRITICAL9Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML s...
CVE-2026-49973CRITICAL9.4Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot...
CVE-2026-47174CRITICAL9.5In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. Th...
CVE-2026-47172CRITICAL9.5Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the r...
CVE-2026-45177CRITICAL9.1Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication...
CVE-2026-49261CRITICAL9.8MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,...
CVE-2026-9648CRITICAL9.1The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi...
CVE-2026-11839CRITICAL9.9Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ...
CVE-2026-38581CRITICAL9.8SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra...
CVE-2026-7852CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu...
CVE-2026-11561CRITICAL9.8Improper neutralization of special elements used in an expression language statement ('expression language injection') v...
CVE-2026-4764CRITICAL9.4A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all...
CVE-2026-41699CRITICAL9.8Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a...
CVE-2026-35273CRITICAL9.8Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana...
CVE-2026-46703CRITICAL9.6Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ...
CVE-2026-46695CRITICAL10Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ...
CVE-2026-0274CRITICAL9.1An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X...
CVE-2026-50638CRITICAL9.1Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd p...
CVE-2026-50566CRITICAL9.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-50564CRITICAL9.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-50563CRITICAL9.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-50545CRITICAL9.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-46614CRITICAL9.8Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-20253CRITICAL9.8In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now