2026 CVE Vulnerabilities

45,093 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-39958CRITICAL9.1oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repos...
CVE-2026-30479CRITICAL9.1A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitr...
CVE-2026-5445CRITICAL9.1An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The looku...
CVE-2026-5443CRITICAL9.8A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation...
CVE-2026-5442CRITICAL9.8A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Represe...
CVE-2026-34184CRITICAL9.1AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all file...
CVE-2026-34179CRITICAL9.1In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate th...
CVE-2026-34178CRITICAL9.1In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supp...
CVE-2026-34177CRITICAL9.1Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limit...
CVE-2026-5854CRITICAL9.8A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEas...
CVE-2026-5853CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t...
CVE-2026-5852CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file...
CVE-2026-5851CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of th...
CVE-2026-5850CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the ...
CVE-2026-5849CRITICAL9.8A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component...
CVE-2026-5841CRITICAL9.8A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of ...
CVE-2026-1830CRITICAL9.8The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1...
CVE-2026-3199CRITICAL9.4A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an a...
CVE-2026-5902CRITICAL9.8Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the rende...
CVE-2026-5874CRITICAL9.6Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to en...
CVE-2026-40035CRITICAL9.3Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo...
CVE-2026-39892CRITICAL9.8cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to b...
CVE-2026-39890CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml li...
CVE-2026-39888CRITICAL9.9PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults...
CVE-2026-39429CRITICAL9.1kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now