2026 CVE Vulnerabilities

45,067 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6920CRITICAL9.6Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromi...
CVE-2026-6919CRITICAL9.6Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the re...
CVE-2026-31533CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of...
CVE-2026-31181CRITICAL9.8An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31178CRITICAL9.8An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31177CRITICAL9.8An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31175CRITICAL9.8An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-40472CRITICAL9.9In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani...
CVE-2026-40471CRITICAL9.6hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could ...
CVE-2026-40470CRITICAL9.9A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou...
CVE-2026-23751CRITICAL9.8Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecate...
CVE-2026-41460CRITICAL9.8SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoin...
CVE-2026-39440CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote ...
CVE-2026-6887CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing...
CVE-2026-6886CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, ...
CVE-2026-6885CRITICAL9.8Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability,...
CVE-2026-3960CRITICAL9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O...
CVE-2026-41229CRITICAL9.1Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes ...
CVE-2026-41228CRITICAL9.9Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat...
CVE-2026-3844CRITICAL9.8The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-41679CRITICAL10Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202...
CVE-2026-41211CRITICAL10Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac...
CVE-2026-41197CRITICAL9.3Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,...
CVE-2026-41196CRITICAL10Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio...
CVE-2026-5935CRITICAL9.8IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now