2026 CVE Vulnerabilities

44,965 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-44315CRITICAL9.4free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-manag...
CVE-2026-49103CRITICAL9.4Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi...
CVE-2026-45570CRITICAL9.6go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH t...
CVE-2026-8175CRITICAL9.8IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-7876CRITICAL9.1IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client m...
CVE-2026-7524CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links duri...
CVE-2026-46043CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size...
CVE-2026-46039CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length chec...
CVE-2026-45988CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a ...
CVE-2026-45972CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in s...
CVE-2026-45898CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removin...
CVE-2026-35090CRITICAL9.3In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne...
CVE-2026-35087CRITICAL9.3Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter...
CVE-2026-42761CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ...
CVE-2026-42758CRITICAL9.8Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privile...
CVE-2026-42757CRITICAL9.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias...
CVE-2026-42756CRITICAL9.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8...
CVE-2026-42755CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn...
CVE-2026-42748CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web She...
CVE-2026-42747CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas...
CVE-2026-42740CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan ...
CVE-2026-42731CRITICAL9.8Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allow...
CVE-2026-42727CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ...
CVE-2026-8054CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints ...
CVE-2026-49002CRITICAL9.1Access control failure means that an application does not effectively check user access permissions, so that unauthorize...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now