2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-7381CRITICAL9.1Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middle...
CVE-2026-30893CRITICAL9.9Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to befo...
CVE-2026-26015CRITICAL9.8DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing bot...
CVE-2026-5166CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software ...
CVE-2026-41940CRITICAL9.8cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthe...
CVE-2026-38992CRITICAL9.8Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints...
CVE-2026-36841CRITICAL9.8TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in ...
CVE-2026-42523CRITICAL9Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing val...
CVE-2026-42249CRITICAL9.8Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at...
CVE-2026-42248CRITICAL9.8Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe...
CVE-2026-3325CRITICAL10SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/ge...
CVE-2026-7333CRITICAL9.6Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-41446CRITICAL9.8Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints th...
CVE-2026-41397CRITICAL9.6OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries th...
CVE-2026-41386CRITICAL9.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to int...
CVE-2026-3893CRITICAL9.4The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct...
CVE-2026-24178CRITICAL9.8NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentica...
CVE-2026-41873CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnera...
CVE-2026-7321CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in...
CVE-2026-27760CRITICAL9.2OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows ...
CVE-2026-7248CRITICAL9.4A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of t...
CVE-2026-7244CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiF...
CVE-2026-7243CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg...
CVE-2026-7242CRITICAL9.8A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of ...
CVE-2026-7241CRITICAL9.8A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now