2026 CVE Vulnerabilities

45,066 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-41323CRITICAL9.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc...
CVE-2026-33078CRITICAL9.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a ...
CVE-2026-33076CRITICAL9.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the hap...
CVE-2026-40630CRITICAL9.8A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration end...
CVE-2026-40620CRITICAL9.8A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established wi...
CVE-2026-39462CRITICAL9.3A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied ...
CVE-2026-35503CRITICAL9.8A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on th...
CVE-2026-27843CRITICAL9.2A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be...
CVE-2026-25775CRITICAL9.8A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be per...
CVE-2026-41274CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher...
CVE-2026-35431CRITICAL10Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo...
CVE-2026-33819CRITICAL9.8Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
CVE-2026-33102CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...
CVE-2026-26210CRITICAL9.8KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the...
CVE-2026-26150CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-24303CRITICAL9.6Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-41276CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil...
CVE-2026-41268CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln...
CVE-2026-41267CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas...
CVE-2026-41265CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl...
CVE-2026-41264CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl...
CVE-2026-25874CRITICAL9.8LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.load...
CVE-2026-6074CRITICAL9.8Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi...
CVE-2026-41247CRITICAL9.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contai...
CVE-2026-6920CRITICAL9.6Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now