2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6348CRITICAL9.3WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local...
CVE-2026-40962CRITICAL9.8FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data ...
CVE-2026-40504CRITICAL9.8Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows ...
CVE-2026-40959CRITICAL9.3Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
CVE-2026-4880CRITICAL9.8The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPres...
CVE-2026-6388CRITICAL9.1A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an...
CVE-2026-40173CRITICAL9.4Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d...
CVE-2026-6296CRITICAL9.6Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform ...
CVE-2026-5189CRITICAL9.2CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unau...
CVE-2026-6290CRITICAL9.1Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with...
CVE-2026-30993CRITICAL9.8Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() functio...
CVE-2026-20186CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20184CRITICAL9.8A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a...
CVE-2026-20180CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20147CRITICAL9.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman...
CVE-2026-5387CRITICAL9.3The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula...
CVE-2026-30625CRITICAL9.8Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica...
CVE-2026-33808CRITICAL9.1Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify...
CVE-2026-33807CRITICAL9.1@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths...
CVE-2026-3461CRITICAL9.8The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc...
CVE-2026-39842CRITICAL9.9OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne...
CVE-2026-1555CRITICAL9.8The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i...
CVE-2026-39399CRITICAL9.6NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend...
CVE-2026-35589CRITICAL9.3nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili...
CVE-2026-35033CRITICAL9.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now