2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-71278CRITICAL9.8rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont...
CVE-2026-71277CRITICAL9.1rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ...
CVE-2026-71268CRITICAL9.9OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s...
CVE-2026-71267CRITICAL9.8microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name...
CVE-2026-71263CRITICAL9.1The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th...
CVE-2026-71262CRITICAL9.8IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (...
CVE-2026-71256CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden...
CVE-2026-71254CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F...
CVE-2026-71248CRITICAL9.8Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P...
CVE-2026-71238CRITICAL9.1DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ...
CVE-2026-71237CRITICAL9.8Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa...
CVE-2026-71231CRITICAL9.8IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod...
CVE-2026-66747CRITICAL9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across ...
CVE-2026-44945CRITICAL9.1A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An...
CVE-2026-10090CRITICAL9.1A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl...
CVE-2026-10059CRITICAL9.1A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp...
CVE-2026-71214CRITICAL9.8The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur...
CVE-2026-71213CRITICAL9.1Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,...
CVE-2026-71207CRITICAL9.8The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut...
CVE-2026-70376CRITICAL9.6Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.adm...
CVE-2026-64566CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s...
CVE-2026-61486CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc...
CVE-2026-61484CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac...
CVE-2026-5581CRITICAL9.1The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ...
CVE-2026-4431CRITICAL9.1The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now