2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-5964CRITICAL9.8EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec...
CVE-2026-5963CRITICAL9.8EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec...
CVE-2026-6644CRITICAL9.1A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrati...
CVE-2026-6643CRITICAL9.9A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unb...
CVE-2026-32956CRITICAL9.8SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in proces...
CVE-2026-41242CRITICAL9.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers...
CVE-2026-40494CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40493CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40492CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40487CRITICAL9Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen...
CVE-2026-40572CRITICAL9NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (Memo...
CVE-2026-40317CRITICAL9.3NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (Jump...
CVE-2026-40582CRITICAL9.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va...
CVE-2026-40484CRITICAL9.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional...
CVE-2026-40324CRITICAL9.1Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's...
CVE-2026-5720CRITICAL9.1miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause...
CVE-2026-40478CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co...
CVE-2026-40477CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co...
CVE-2026-40351CRITICAL9.8FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScri...
CVE-2026-40258CRITICAL9.1The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 hav...
CVE-2026-29013CRITICAL9.8libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in ...
CVE-2026-33689CRITICAL9.1xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentic...
CVE-2026-23500CRITICAL9.1Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio...
CVE-2026-40342CRITICAL9.9Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the exte...
CVE-2026-35546CRITICAL9.8Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now