2026 CVE Vulnerabilities

44,991 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-43493CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques...
CVE-2026-46725CRITICAL9.2The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ...
CVE-2026-45434CRITICAL9.8Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T...
CVE-2026-41919CRITICAL9.1Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi...
CVE-2026-31986CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U...
CVE-2026-2611CRITICAL9.6In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ...
CVE-2026-4885CRITICAL9.8The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ...
CVE-2026-47314CRITICAL9.8Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:...
CVE-2026-47311CRITICAL9.8Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...
CVE-2026-47310CRITICAL9.8Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: ...
CVE-2026-8838CRITICAL9.8Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver befor...
CVE-2026-27130CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu...
CVE-2026-25244CRITICAL9.8WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appiu...
CVE-2026-8836CRITICAL9.8A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/sn...
CVE-2026-45495CRITICAL9.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-45230CRITICAL9.1DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelet...
CVE-2026-42822CRITICAL10Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges ove...
CVE-2026-45829CRITICAL10A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un...
CVE-2026-41948CRITICAL9.4Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque...
CVE-2026-41947CRITICAL9.3Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set ...
CVE-2026-7304CRITICAL9.8SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo...
CVE-2026-7302CRITICAL9.1SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta...
CVE-2026-7301CRITICAL9.8SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal...
CVE-2026-4320CRITICAL9.3Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr...
CVE-2026-8721CRITICAL9.8Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in P...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now