2026 CVE Vulnerabilities

44,967 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-8760CRITICAL9.8The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6...
CVE-2026-8450CRITICAL9.1HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg...
CVE-2026-44985CRITICAL9.6Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach ...
CVE-2026-44966CRITICAL9.8Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pol...
CVE-2026-44895CRITICAL9.2GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships...
CVE-2026-44451CRITICAL9.3Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied...
CVE-2026-44450CRITICAL9.9Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command...
CVE-2026-44449CRITICAL9.1Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the ...
CVE-2026-44444CRITICAL9.1Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install...
CVE-2026-48689CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffe...
CVE-2026-3660CRITICAL9.8IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update se...
CVE-2026-9170CRITICAL9.8IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper in...
CVE-2026-8856CRITICAL9.1IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to ...
CVE-2026-8855CRITICAL9.8IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut...
CVE-2026-8633CRITICAL9.8IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server...
CVE-2026-7251CRITICAL9.8Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network...
CVE-2026-47202CRITICAL9.3Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau...
CVE-2026-46624CRITICAL9.9Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in ...
CVE-2026-44668CRITICAL9.8FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the aut...
CVE-2026-48904CRITICAL9.8An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48902CRITICAL9.8The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't e...
CVE-2026-48899CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48691CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp...
CVE-2026-45721CRITICAL9Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now