2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-53476CRITICAL9.6A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),...
CVE-2026-45558CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45556CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO...
CVE-2026-45552CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45550CRITICAL9.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PU...
CVE-2026-9067CRITICAL9.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ...
CVE-2026-26241CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-26240CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-44963CRITICAL9.4A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2026-48303CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil...
CVE-2026-47938CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) ...
CVE-2026-47928CRITICAL9.6ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-36727CRITICAL9.1An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass...
CVE-2026-36721CRITICAL9.8A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to ...
CVE-2026-30141CRITICAL9.8An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attack...
CVE-2026-10045CRITICAL9.8Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded ...
CVE-2026-34691CRITICAL9.3Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ...
CVE-2026-49841CRITICAL9.8FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49840CRITICAL9.1FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-47643CRITICAL9.8External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network...
CVE-2026-47291CRITICAL9.8Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
CVE-2026-47281CRITICAL9.6Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-45657CRITICAL9.8Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVE-2026-45602CRITICAL9.1No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
CVE-2026-44815CRITICAL9.8Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now