2026 CVE Vulnerabilities

45,004 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25787CRITICAL9.3Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagn...
CVE-2026-25786CRITICAL9.3Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page ...
CVE-2026-22924CRITICAL9.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly...
CVE-2026-41872CRITICAL9.1"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle at...
CVE-2026-34263CRITICAL9.6Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in...
CVE-2026-34260CRITICAL9.6SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacke...
CVE-2026-45321CRITICAL9.6On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ...
CVE-2026-43914CRITICAL9.8Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul...
CVE-2026-43900CRITICAL9.3DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0....
CVE-2026-43899CRITICAL9.6DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0....
CVE-2026-42882CRITICAL9.4oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ...
CVE-2026-42869CRITICAL10SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,...
CVE-2026-42864CRITICAL9.9FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ...
CVE-2026-8305CRITICAL9.8A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR...
CVE-2026-43995CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool i...
CVE-2026-43639CRITICAL9.1Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t...
CVE-2026-42858CRITICAL9.9Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in...
CVE-2026-38567CRITICAL9.8HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated di...
CVE-2026-7813CRITICAL9.9Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces...
CVE-2026-44643CRITICAL10Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att...
CVE-2026-42613CRITICAL9.4Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attac...
CVE-2026-42608CRITICAL9.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c...
CVE-2026-42607CRITICAL9.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie...
CVE-2026-35157CRITICAL9.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutraliz...
CVE-2026-8263CRITICAL9.8A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now