2026 CVE Vulnerabilities

44,810 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-49448CRITICAL9.8authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can...
CVE-2026-42849CRITICAL9.3authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st...
CVE-2026-5076CRITICAL9.8The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a...
CVE-2026-38967CRITICAL9.8CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
CVE-2026-42074CRITICAL9.8OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0...
CVE-2026-0611CRITICAL9.8Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code...
CVE-2026-47117CRITICAL9.8OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The pr...
CVE-2026-7198CRITICAL9.8CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut...
CVE-2026-10611CRITICAL10An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In...
CVE-2026-42684CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta...
CVE-2026-34906CRITICAL9.3Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex...
CVE-2026-8206CRITICAL9.8The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalati...
CVE-2026-25879CRITICAL9.8Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent ex...
CVE-2026-40965CRITICAL10Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vul...
CVE-2026-9319CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of...
CVE-2026-9311CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co...
CVE-2026-8644CRITICAL9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-49121CRITICAL9.8AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the ...
CVE-2026-22872CRITICAL9.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri...
CVE-2026-45132CRITICAL10CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow ...
CVE-2026-45131CRITICAL10CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow ...
CVE-2026-44211CRITICAL9.6Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a...
CVE-2026-42672CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W...
CVE-2026-8931CRITICAL9.4A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
CVE-2026-48879CRITICAL9.8Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now