2026 CVE Vulnerabilities

43,098 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-65508CRITICAL9.3Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65507CRITICAL9.8Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
CVE-2026-54489CRITICAL9.8Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati...
CVE-2026-53976CRITICAL9.3OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and...
CVE-2026-53975CRITICAL9.8OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu...
CVE-2026-34191CRITICAL9.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru...
CVE-2026-32327CRITICAL9.1A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses ...
CVE-2026-28139CRITICAL9.8Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-28005CRITICAL9.8Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-64993CRITICAL9.1Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo...
CVE-2026-5134CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info...
CVE-2026-12605CRITICAL9.6In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt...
CVE-2026-68079CRITICAL9.8In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of ...
CVE-2026-65583CRITICAL9.1Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che...
CVE-2026-63687CRITICAL9.1Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho...
CVE-2026-61466CRITICAL9.1In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val...
CVE-2026-66909CRITICAL9.8Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit...
CVE-2026-64597CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay...
CVE-2026-5430CRITICAL10The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support...
CVE-2026-1728CRITICAL9.8Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level...
CVE-2026-16054CRITICAL9.1The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us...
CVE-2026-12713CRITICAL9.1The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i...
CVE-2026-67873CRITICAL9.8A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ...
CVE-2026-67870CRITICAL9.8In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E...
CVE-2026-67531CRITICAL9.3FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now