2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-48241CRITICAL9.2Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut...
CVE-2026-48207CRITICAL9.8Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati...
CVE-2026-39531CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W...
CVE-2026-5118CRITICAL9.8The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2...
CVE-2026-43501CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompress...
CVE-2026-5433CRITICAL9.1Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could ...
CVE-2026-4858CRITICAL9.9Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration ...
CVE-2026-44050CRITICAL9.9A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote auth...
CVE-2026-6279CRITICAL9.8The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F...
CVE-2026-9152CRITICAL10A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind...
CVE-2026-48172CRITICAL9.8LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i...
CVE-2026-47372CRITICAL9.1Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil...
CVE-2026-8631CRITICAL9.8A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul...
CVE-2026-9141CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web...
CVE-2026-9139CRITICAL9.8Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web ...
CVE-2026-9129CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling ...
CVE-2026-9102CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza...
CVE-2026-9082CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core...
CVE-2026-45444CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using M...
CVE-2026-39405CRITICAL9.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50....
CVE-2026-33137CRITICAL9.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2026-23734CRITICAL9.3XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to ...
CVE-2026-20223CRITICAL10A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica...
CVE-2026-8598CRITICAL9.1An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi...
CVE-2026-8467CRITICAL9.5Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now