2026 CVE Vulnerabilities

44,992 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-8580CRITICAL9.6Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandb...
CVE-2026-8511CRITICAL9.6Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox...
CVE-2026-26191CRITICAL9.8Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer ...
CVE-2026-45375CRITICAL9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) r...
CVE-2026-44670CRITICAL9.4SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / da...
CVE-2026-44592CRITICAL9.4Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the N...
CVE-2026-44588CRITICAL9.4SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/...
CVE-2026-44523CRITICAL10Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW...
CVE-2026-41315CRITICAL9.8mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command ex...
CVE-2026-46470CRITICAL9.1An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ...
CVE-2026-44542CRITICAL9.1FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-contr...
CVE-2026-42555CRITICAL9.1Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32...
CVE-2026-20182CRITICAL10May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi...
CVE-2026-42596CRITICAL9.4Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d...
CVE-2026-42589CRITICAL9.8Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write...
CVE-2026-44484CRITICAL9.8PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu...
CVE-2026-44482CRITICAL9.6soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8...
CVE-2026-42457CRITICAL9vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio...
CVE-2026-2347CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Comme...
CVE-2026-6512CRITICAL9.1The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1....
CVE-2026-6510CRITICAL9.8The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions ...
CVE-2026-6271CRITICAL9.8The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7...
CVE-2026-8181CRITICAL9.8The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulne...
CVE-2026-8500CRITICAL9.8Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing ht...
CVE-2026-45158CRITICAL9.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now