2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34457CRITICAL9.1OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a ...
CVE-2026-39907CRITICAL10Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on ...
CVE-2026-39906CRITICAL10Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel t...
CVE-2026-27304CRITICAL9.3ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-5752CRITICAL9.3Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via Jav...
CVE-2026-34615CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that ...
CVE-2026-33824CRITICAL9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-27303CRITICAL9.6Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that ...
CVE-2026-27246CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-27245CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-27243CRITICAL9.3Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A...
CVE-2026-26149CRITICAL9Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to p...
CVE-2026-39813CRITICAL9.8A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4....
CVE-2026-39808CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2026-38526CRITICAL9.9An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a...
CVE-2026-31049CRITICAL9.8An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile...
CVE-2026-2449CRITICAL9Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u...
CVE-2026-2332CRITICAL9.1In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the ...
CVE-2026-31908CRITICAL9.1Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au...
CVE-2026-40315CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC...
CVE-2026-40313CRITICAL9.1PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A...
CVE-2026-40289CRITICAL9.1PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow...
CVE-2026-40288CRITICAL9.8PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work...
CVE-2026-6264CRITICAL9.8A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the...
CVE-2026-4365CRITICAL9.1The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now