2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-40050CRITICAL9.8CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-4...
CVE-2026-38835CRITICAL9.8Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount func...
CVE-2026-40498CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ...
CVE-2026-6771CRITICAL9.8Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund...
CVE-2026-6768CRITICAL9.8Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6760CRITICAL9.8Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6748CRITICAL9.8Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ...
CVE-2026-5965CRITICAL9.8NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to in...
CVE-2026-40496CRITICAL9.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g...
CVE-2026-39861CRITICAL10Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processe...
CVE-2026-41329CRITICAL9.9OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbea...
CVE-2026-5450CRITICAL9.8Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version ...
CVE-2026-33432CRITICAL9.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8...
CVE-2026-32613CRITICAL9.9Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring ...
CVE-2026-32604CRITICAL9.9Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2...
CVE-2026-29646CRITICAL9.8In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to t...
CVE-2026-6257CRITICAL9.2Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ...
CVE-2026-32311CRITICAL9.8Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-29649CRITICAL9.8NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f...
CVE-2026-39109CRITICAL9.4SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the...
CVE-2026-30269CRITICAL9.9Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a...
CVE-2026-39918CRITICAL9.8Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parame...
CVE-2026-24467CRITICAL9.8OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa...
CVE-2026-5760CRITICAL9.8SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious to...
CVE-2026-33557CRITICAL9.1A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now