2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27681CRITICAL9.9Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe...
CVE-2026-22564CRITICAL9.8An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable S...
CVE-2026-22563CRITICAL9.8A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t...
CVE-2026-22562CRITICAL9.8A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device...
CVE-2026-31048CRITICAL9.8An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra...
CVE-2026-40044CRITICAL9.8Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by...
CVE-2026-40042CRITICAL9.8Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbit...
CVE-2026-6195CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the funct...
CVE-2026-6100CRITICAL9.1Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo...
CVE-2026-31283CRITICAL9.8In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address....
CVE-2026-31282CRITICAL9.8Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea...
CVE-2026-31414CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper ...
CVE-2026-4810CRITICAL9.3A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0....
CVE-2026-0234CRITICAL9.1An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms duri...
CVE-2026-5936CRITICAL9.8An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests t...
CVE-2026-5085CRITICAL9.1Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return...
CVE-2026-34865CRITICAL9.1Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av...
CVE-2026-40446CRITICAL9.8Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point...
CVE-2026-25209CRITICAL9.1Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg...
CVE-2026-25208CRITICAL9.8Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8...
CVE-2026-25207CRITICAL9.8Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 9...
CVE-2026-25206CRITICAL9.1Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg...
CVE-2026-25205CRITICAL9.8Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects E...
CVE-2026-6156CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosR...
CVE-2026-6155CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now