2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-24425CRITICAL9.9Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface ...
CVE-2026-3593CRITICAL9.8A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20....
CVE-2026-22314CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesa...
CVE-2026-42960CRITICAL10NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori...
CVE-2026-33278CRITICAL9.8NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de...
CVE-2026-9065CRITICAL9.3SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'mo...
CVE-2026-9059CRITICAL9.3NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the ...
CVE-2026-7637CRITICAL9.8The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria...
CVE-2026-24214CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove...
CVE-2026-24213CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun...
CVE-2026-24207CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes...
CVE-2026-24206CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes...
CVE-2026-24163CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri...
CVE-2026-24142CRITICAL9.8NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful ex...
CVE-2026-7284CRITICAL9.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation ...
CVE-2026-6555CRITICAL9.8The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, ...
CVE-2026-8495CRITICAL9.8Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0....
CVE-2026-34234CRITICAL10CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p...
CVE-2026-33642CRITICAL9.8Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit...
CVE-2026-8605CRITICAL9.8In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst...
CVE-2026-8603CRITICAL9.8In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t...
CVE-2026-8602CRITICAL9.1In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at...
CVE-2026-36829CRITICAL9.8An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7....
CVE-2026-37281CRITICAL9.8An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo...
CVE-2026-31072CRITICAL9.8The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now