2026 CVE Vulnerabilities

45,029 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-7414CRITICAL9.8Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar...
CVE-2026-7413CRITICAL9.8A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen...
CVE-2026-7821CRITICAL9.1Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen...
CVE-2026-5788CRITICAL9.8An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat...
CVE-2026-5787CRITICAL9.1An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut...
CVE-2026-36458CRITICAL9.8ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated i...
CVE-2026-6795CRITICAL9.6URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive...
CVE-2026-41589CRITICAL9.6Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP...
CVE-2026-30496CRITICAL9.8The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that...
CVE-2026-8094CRITICAL9.8Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVE-2026-8091CRITICAL9.8Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thund...
CVE-2026-6508CRITICAL9.8Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Acces...
CVE-2026-42010CRITICAL9.8A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched ...
CVE-2026-33587CRITICAL10Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque...
CVE-2026-41586CRITICAL9.3Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica...
CVE-2026-44603CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CVE-2026-42217CRITICAL9.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-42216CRITICAL9.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-41203CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41202CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41201CRITICAL9.1CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-40982CRITICAL9.1Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server ...
CVE-2026-44597CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,...
CVE-2026-40281CRITICAL9.1Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v...
CVE-2026-44112CRITICAL9.6OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now