2026 CVE Vulnerabilities

44,115 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-42904CRITICAL9.6Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent netw...
CVE-2026-38615CRITICAL9.8DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-34182CRITICAL9.1Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe...
CVE-2026-26142CRITICAL9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-8025CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T...
CVE-2026-25089CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2026-10523CRITICAL9.8An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow...
CVE-2026-10520CRITICAL10An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote ...
CVE-2026-7486CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In...
CVE-2026-46325CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz...
CVE-2026-46316CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re...
CVE-2026-46749CRITICAL9.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas...
CVE-2026-41031CRITICAL9.3A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an ...
CVE-2026-10731CRITICAL9.3SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u...
CVE-2026-9698CRITICAL9.8DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Raise...
CVE-2026-44083CRITICAL9.8An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack...
CVE-2026-5067CRITICAL9.8A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi...
CVE-2026-41855CRITICAL9.8In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin...
CVE-2026-44748CRITICAL9.9SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai...
CVE-2026-40128CRITICAL9SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon...
CVE-2026-27671CRITICAL9.8Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ...
CVE-2026-11697CRITICAL9.6Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p...
CVE-2026-11671CRITICAL9.6Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a...
CVE-2026-11659CRITICAL9.6Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perfor...
CVE-2026-11654CRITICAL9.6Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now