2026 CVE Vulnerabilities

44,992 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-8507CRITICAL9.8Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file,...
CVE-2026-8757CRITICAL9.1A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/fram...
CVE-2026-8751CRITICAL9.8A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h...
CVE-2026-44566CRITICAL9.8Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, whe...
CVE-2026-8696CRITICAL9.8radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that a...
CVE-2026-44551CRITICAL9.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L...
CVE-2026-8686CRITICAL9.1Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a den...
CVE-2026-46364CRITICAL9.8phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and ...
CVE-2026-45010CRITICAL9.3phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/...
CVE-2026-8695CRITICAL9.8radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t...
CVE-2026-44774CRITICAL9.9Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP...
CVE-2026-44717CRITICAL9.8MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the ...
CVE-2026-44699CRITICAL9.1LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame...
CVE-2026-42155CRITICAL9.3Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-41258CRITICAL9.1OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe...
CVE-2026-45772CRITICAL9.8Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo...
CVE-2026-2031CRITICAL10An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio...
CVE-2026-7182CRITICAL9.2Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti...
CVE-2026-41553CRITICAL10PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "d...
CVE-2026-8398CRITICAL9.8A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 ...
CVE-2026-5229CRITICAL9.8The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This...
CVE-2026-0481CRITICAL9.2Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per...
CVE-2026-44666CRITICAL9.3HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri...
CVE-2026-44212CRITICAL9.3PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scriptin...
CVE-2026-8634CRITICAL9.3Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now