2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-40330CRITICAL9.3Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu...
CVE-2026-40329CRITICAL9.3Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist...
CVE-2026-34084CRITICAL9.8PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1...
CVE-2026-7854CRITICAL9.8A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ...
CVE-2026-38428CRITICAL9.8Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a G...
CVE-2026-27960CRITICAL9.8OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 t...
CVE-2026-7853CRITICAL9.8A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.a...
CVE-2026-38431CRITICAL9.8ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to crea...
CVE-2026-38429CRITICAL9.8OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML par...
CVE-2026-7411CRITICAL10In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTT...
CVE-2026-43071CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two ...
CVE-2026-43067CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks f...
CVE-2026-34002CRITICAL9.1A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension...
CVE-2026-34000CRITICAL9.1A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifical...
CVE-2026-7834CRITICAL9.8A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_white...
CVE-2026-36356CRITICAL9.1The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica...
CVE-2026-34408CRITICAL9.1An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset f...
CVE-2026-43566CRITICAL9.8OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade...
CVE-2026-43534CRITICAL9.8OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a...
CVE-2026-43526CRITICAL9.3OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that al...
CVE-2026-40797CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC We...
CVE-2026-7823CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of...
CVE-2026-5294CRITICAL9.8The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This ...
CVE-2026-5722CRITICAL9.8The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1....
CVE-2026-42238CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore end...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now