2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-31071CRITICAL9.1API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated...
CVE-2026-31070CRITICAL9.8The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg...
CVE-2026-30118CRITICAL9.8scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of...
CVE-2026-30117CRITICAL9.8scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame...
CVE-2026-8711CRITICAL9.8NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled...
CVE-2026-44159CRITICAL9.8Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c...
CVE-2026-2587CRITICAL9.6A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used...
CVE-2026-2586CRITICAL9.1An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ...
CVE-2026-8959CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire...
CVE-2026-8956CRITICAL9.8Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thun...
CVE-2026-8953CRITICAL9.6Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-8950CRITICAL9.3Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14...
CVE-2026-8948CRITICAL9.1Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-47323CRITICAL9.8Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra...
CVE-2026-43633CRITICAL10HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ...
CVE-2026-4883CRITICAL9.8The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the...
CVE-2026-43493CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques...
CVE-2026-46725CRITICAL9.2The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ...
CVE-2026-45434CRITICAL9.8Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T...
CVE-2026-41919CRITICAL9.1Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi...
CVE-2026-31986CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U...
CVE-2026-2611CRITICAL9.6In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ...
CVE-2026-4885CRITICAL9.8The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ...
CVE-2026-47314CRITICAL9.8Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:...
CVE-2026-47311CRITICAL9.8Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now