2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-24120CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca...
CVE-2026-24118CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-7482CRITICAL9.1Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint...
CVE-2026-7747CRITICAL9.8A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function l...
CVE-2026-29200CRITICAL9.9A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2...
CVE-2026-7719CRITICAL9.8A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginau...
CVE-2026-7372CRITICAL9A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A special...
CVE-2026-7161CRITICAL9.3An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Uti...
CVE-2026-42370CRITICAL9.8A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A special...
CVE-2026-42369CRITICAL10GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other securit...
CVE-2026-42368CRITICAL9.9A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A spec...
CVE-2026-7690CRITICAL9.8A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm o...
CVE-2026-7458CRITICAL9.8The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, ...
CVE-2026-4882CRITICAL9.8The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...
CVE-2026-37541CRITICAL10Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length fi...
CVE-2026-37540CRITICAL9.8OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it ...
CVE-2026-37539CRITICAL9.8Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and dec...
CVE-2026-37534CRITICAL9.8Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in S...
CVE-2026-37531CRITICAL9.8AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU rac...
CVE-2026-42473CRITICAL9.8Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize...
CVE-2026-42472CRITICAL9.8Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize...
CVE-2026-43039CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wr...
CVE-2026-43038CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_...
CVE-2026-43037CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar...
CVE-2026-43011CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When all...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now