2026 CVE Vulnerabilities

44,809 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-36182CRITICAL9.8GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta...
CVE-2026-10868CRITICAL9A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie...
CVE-2026-35906CRITICAL9.6An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at...
CVE-2026-35905CRITICAL9.8T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded passw...
CVE-2026-35904CRITICAL9.8Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an...
CVE-2026-8037CRITICAL9.8OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated atta...
CVE-2026-4104CRITICAL9.8Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ...
CVE-2026-50225CRITICAL9.1The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t...
CVE-2026-50214CRITICAL9.8The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary...
CVE-2026-50211CRITICAL9.8Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious...
CVE-2026-50208CRITICAL9.4High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc...
CVE-2026-49191CRITICAL9.8The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose...
CVE-2026-49188CRITICAL9.8The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u...
CVE-2026-49186CRITICAL9.8The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin...
CVE-2026-49185CRITICAL9.8The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction...
CVE-2026-41283CRITICAL9.9OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha...
CVE-2026-46266CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incom...
CVE-2026-46244CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync ...
CVE-2026-36748CRITICAL9RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
CVE-2026-36576CRITICAL9.8An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al...
CVE-2026-5241CRITICAL9.6A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control...
CVE-2026-35075CRITICAL9.8An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a...
CVE-2026-47065CRITICAL9.8ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful...
CVE-2026-35482CRITICAL9.1alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2026-32625CRITICAL9.6LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the M...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now