2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-11414CRITICAL9.8A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Beca...
CVE-2026-46496CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-46399CRITICAL9.4HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 ...
CVE-2026-46396CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-46395CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio...
CVE-2026-46389CRITICAL9.8UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Co...
CVE-2026-10580CRITICAL9.8The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat...
CVE-2026-45750CRITICAL9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-45748CRITICAL9.8Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST ...
CVE-2026-45746CRITICAL9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-45744CRITICAL9.9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-36500CRITICAL9.1An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory t...
CVE-2026-9270CRITICAL9.1DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitis...
CVE-2026-11362CRITICAL9.8DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not ...
CVE-2026-10879CRITICAL9.8DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The pr...
CVE-2026-6274CRITICAL9.8Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron...
CVE-2026-49777CRITICAL10Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce...
CVE-2026-48907CRITICAL9.8A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated us...
CVE-2026-7763CRITICAL9.8A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software...
CVE-2026-7762CRITICAL9.8A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 softwa...
CVE-2026-11293CRITICAL9.6Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandb...
CVE-2026-11282CRITICAL9.6Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to...
CVE-2026-11250CRITICAL9.6Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compr...
CVE-2026-48567CRITICAL9.8Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-11213CRITICAL9.6Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now