2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-69256CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no...
CVE-2026-69255CRITICAL9.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in...
CVE-2026-64633CRITICAL10A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-63456CRITICAL9.8Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2026-63455CRITICAL9.8Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2026-58073CRITICAL9.5A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an...
CVE-2026-58072CRITICAL9A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead...
CVE-2026-69254CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri...
CVE-2026-69253CRITICAL9Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1...
CVE-2026-69110CRITICAL9.3OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker...
CVE-2026-69098CRITICAL9.8kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows ...
CVE-2026-25289CRITICAL9.6Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with inv...
CVE-2026-18801CRITICAL9.3OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ...
CVE-2026-69251CRITICAL9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ...
CVE-2026-61515CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo...
CVE-2026-61514CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent...
CVE-2026-10050CRITICAL9.1In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th...
CVE-2026-15721CRITICAL9.8Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig...
CVE-2026-14804CRITICAL9.1Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu...
CVE-2026-14175CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS...
CVE-2026-18754CRITICAL9.1The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio...
CVE-2026-18753CRITICAL9.1The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio...
CVE-2026-64564CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-...
CVE-2026-16618CRITICAL9.8The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten...
CVE-2026-15958CRITICAL9.3The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now