2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-66321CRITICAL9.6Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-18686CRITICAL9.8A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of ...
CVE-2026-18685CRITICAL9.8A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the...
CVE-2026-48333CRITICAL9.8Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca...
CVE-2026-48331CRITICAL10Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv...
CVE-2026-48330CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48326CRITICAL9.9Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48323CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul...
CVE-2026-48317CRITICAL9.6Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva...
CVE-2026-18684CRITICAL9.8A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f...
CVE-2026-18667CRITICAL9.6A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an...
CVE-2026-46713CRITICAL9.2Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a...
CVE-2026-69240CRITICAL9.8Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl...
CVE-2026-52102CRITICAL9.8An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe...
CVE-2026-51775CRITICAL9.8SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati...
CVE-2026-51190CRITICAL9.8The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw...
CVE-2026-48063CRITICAL9.3Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile...
CVE-2026-68980CRITICAL9.1Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu...
CVE-2026-68979CRITICAL9.8Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization...
CVE-2026-67598CRITICAL9.1Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all...
CVE-2026-48031CRITICAL9.1go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202...
CVE-2026-38447CRITICAL9.8osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ...
CVE-2026-18616CRITICAL9.8A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of...
CVE-2026-18615CRITICAL9.8A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate...
CVE-2026-18614CRITICAL9.8A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now