2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-33516CRITICAL9.1xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP ca...
CVE-2026-40525CRITICAL9.1OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su...
CVE-2026-40518CRITICAL9.1ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-m...
CVE-2026-6284CRITICAL9.3An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst...
CVE-2026-41153CRITICAL9.8In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
CVE-2026-37749CRITICAL9.8A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attack...
CVE-2026-6443CRITICAL9.8All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to ...
CVE-2026-34018CRITICAL9.8An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQ...
CVE-2026-40322CRITICAL9SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendere...
CVE-2026-33122CRITICAL9.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33082CRITICAL9.8DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab...
CVE-2026-27820CRITICAL9.8zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 a...
CVE-2026-5426CRITICAL9.1Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all...
CVE-2026-37347CRITICAL9.1SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_e...
CVE-2026-37345CRITICAL9.8SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_pa...
CVE-2026-37340CRITICAL9.8SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php...
CVE-2026-37339CRITICAL9.8SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php...
CVE-2026-37338CRITICAL9.4SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
CVE-2026-33804CRITICAL9.1@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplica...
CVE-2026-6270CRITICAL9.1@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instance...
CVE-2026-31843CRITICAL10The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update e...
CVE-2026-3596CRITICAL9.8The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2026-22619CRITICAL9.9Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to a...
CVE-2026-6350CRITICAL9.8MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remo...
CVE-2026-6349CRITICAL9.8The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now