2026 CVE Vulnerabilities

45,006 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6104CRITICAL9.1In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is pas...
CVE-2026-7261CRITICAL9.8In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i...
CVE-2026-6722CRITICAL9.8In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio...
CVE-2026-42601CRITICAL9.8ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddVi...
CVE-2026-42571CRITICAL9Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.2...
CVE-2026-42569CRITICAL9.4phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS a...
CVE-2026-42257CRITICAL9.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5...
CVE-2026-42560CRITICAL9.1auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1...
CVE-2026-6665CRITICAL9.8The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten...
CVE-2026-44313CRITICAL9.1Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior...
CVE-2026-42556CRITICAL9Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c...
CVE-2026-42454CRITICAL9.9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42354CRITICAL9.8Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical v...
CVE-2026-42302CRITICAL9.8FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of...
CVE-2026-42298CRITICAL9.8Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Pu...
CVE-2026-42287CRITICAL10Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u...
CVE-2026-42193CRITICAL9.1Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep...
CVE-2026-44400CRITICAL9.8MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ...
CVE-2026-44694CRITICAL9.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ...
CVE-2026-42160CRITICAL10Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F...
CVE-2026-8178CRITICAL9.2An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ...
CVE-2026-42072CRITICAL9.8Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri...
CVE-2026-41889CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp...
CVE-2026-38360CRITICAL9.8Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut...
CVE-2026-41070CRITICAL10openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now