2026 CVE Vulnerabilities

45,099 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-20884CRITICAL9.8An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially...
CVE-2026-5735CRITICAL9.8Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corr...
CVE-2026-5734CRITICAL9.8Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Som...
CVE-2026-5731CRITICAL9.8Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Th...
CVE-2026-28808CRITICAL9.8Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protect...
CVE-2026-23818CRITICAL9.6A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Pre...
CVE-2026-22679CRITICAL9.8Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability ...
CVE-2026-1114CRITICAL9.8In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to t...
CVE-2026-0740CRITICAL9.8The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2026-35471CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal chec...
CVE-2026-35408CRITICAL9.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig...
CVE-2026-35393CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. Thi...
CVE-2026-35392CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitiz...
CVE-2026-35459CRITICAL9.1pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-s...
CVE-2026-35197CRITICAL9.8dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would...
CVE-2026-35184CRITICAL9.8EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/template...
CVE-2026-35178CRITICAL9.8Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo...
CVE-2026-35171CRITICAL9.8Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path t...
CVE-2026-35052CRITICAL9.8D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3...
CVE-2026-35047CRITICAL9.8Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allo...
CVE-2026-35044CRITICAL9.6BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-35039CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil...
CVE-2026-35035CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-35030CRITICAL9.4LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authenti...
CVE-2026-34989CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now