2026 CVE Vulnerabilities

44,958 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-45787CRITICAL9.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic ...
CVE-2026-45374CRITICAL9.6CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents...
CVE-2026-45323CRITICAL9.6MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered witho...
CVE-2026-45311CRITICAL9.6CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in...
CVE-2026-45058CRITICAL9.4electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is...
CVE-2026-43898CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing...
CVE-2026-9098CRITICAL9.1In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLRe...
CVE-2026-9097CRITICAL9.8Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExcha...
CVE-2026-9094CRITICAL9.8Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExc...
CVE-2026-9093CRITICAL9.8In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestrict...
CVE-2026-9092CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account ...
CVE-2026-9090CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplyi...
CVE-2026-45261CRITICAL9.3GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut...
CVE-2026-44477CRITICAL9.9CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and ...
CVE-2026-38707CRITICAL9.8A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm...
CVE-2026-38704CRITICAL9.8A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ...
CVE-2026-38703CRITICAL9.8A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-38702CRITICAL9.8A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-24444CRITICAL9.8SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ...
CVE-2026-44672CRITICAL9.3mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30...
CVE-2026-8980CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv...
CVE-2026-8979CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re...
CVE-2026-9813CRITICAL9.9FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL ...
CVE-2026-46195CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DA...
CVE-2026-46185CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data(...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now