2026 CVE Vulnerabilities

44,810 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-48866CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit...
CVE-2026-42682CRITICAL9.1Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-42680CRITICAL9.8Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P...
CVE-2026-0826CRITICAL9.2In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could en...
CVE-2026-7858CRITICAL9.8A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic ...
CVE-2026-44825CRITICAL9.8Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug...
CVE-2026-42252CRITICAL9.1Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show...
CVE-2026-48188CRITICAL9.1An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthe...
CVE-2026-10187CRITICAL9.8A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasic...
CVE-2026-45700CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an...
CVE-2026-45697CRITICAL9.8Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted ...
CVE-2026-45372CRITICAL9.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's se...
CVE-2026-9051CRITICAL9.3There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ...
CVE-2026-47744CRITICAL9.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al...
CVE-2026-44650CRITICAL9.1SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44649CRITICAL9.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-7786CRITICAL9.8Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex...
CVE-2026-5386CRITICAL9.1The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an ...
CVE-2026-45668CRITICAL9.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-45661CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab...
CVE-2026-45633CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti...
CVE-2026-45632CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor...
CVE-2026-45631CRITICAL10Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC...
CVE-2026-45630CRITICAL9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45629CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now