2026 CVE Vulnerabilities

45,110 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-5368CRITICAL9.8A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of t...
CVE-2026-34877CRITICAL9.8An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of seriali...
CVE-2026-33950CRITICAL9.4Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a...
CVE-2026-25212CRITICAL9.9An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileg...
CVE-2026-33746CRITICAL9.8Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWT...
CVE-2026-35002CRITICAL9.8Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that al...
CVE-2026-32871CRITICAL10FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos...
CVE-2026-5334CRITICAL9.8A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file...
CVE-2026-5333CRITICAL9.8A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown pro...
CVE-2026-2699CRITICAL9.8Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted config...
CVE-2026-33615CRITICAL9.1An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint du...
CVE-2026-29143CRITICAL9.1SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted...
CVE-2026-29139CRITICAL9.8SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to re...
CVE-2026-29133CRITICAL9.1SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match th...
CVE-2026-5244CRITICAL9.8A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mo...
CVE-2026-34571CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34569CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34568CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34567CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34566CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34565CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34564CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34563CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34562CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34560CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now