2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-42484CRITICAL9.8A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a d...
CVE-2026-42483CRITICAL9.8A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of servi...
CVE-2026-42482CRITICAL9.8A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allow...
CVE-2026-31718CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via...
CVE-2026-31705CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA ...
CVE-2026-42779CRITICAL9.8The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ...
CVE-2026-42778CRITICAL9.8The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ...
CVE-2026-7567CRITICAL9.8The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. T...
CVE-2026-42996CRITICAL10JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @AP...
CVE-2026-42994CRITICAL9.8Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code....
CVE-2026-7546CRITICAL9.8A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the functi...
CVE-2026-7538CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of...
CVE-2026-40687CRITICAL9.1In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-...
CVE-2026-40685CRITICAL9.8In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter...
CVE-2026-2311CRITICAL9.8IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI...
CVE-2026-39858CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s...
CVE-2026-35051CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe...
CVE-2026-33447CRITICAL9.8CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers...
CVE-2026-33446CRITICAL9.8CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attack...
CVE-2026-33845CRITICAL9.1A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i...
CVE-2026-36767CRITICAL10A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary f...
CVE-2026-36760CRITICAL9.6An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with ...
CVE-2026-4670CRITICAL9.8Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Byp...
CVE-2026-42799CRITICAL9.8Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associa...
CVE-2026-22070CRITICAL9.8ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now