2026 CVE Vulnerabilities

45,110 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34559CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-4101CRITICAL9.8IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-34873CRITICAL9.1An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session...
CVE-2026-34529CRITICAL9File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-34528CRITICAL9.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-34520CRITICAL9.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (t...
CVE-2026-34872CRITICAL9.1An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory...
CVE-2026-34456CRITICAL9.8Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From ver...
CVE-2026-34875CRITICAL9.8An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key exp...
CVE-2026-34751CRITICAL9.1Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and...
CVE-2026-34236CRITICAL9.8Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app...
CVE-2026-34159CRITICAL9.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor()...
CVE-2026-34072CRITICAL9.8Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs...
CVE-2026-33990CRITICAL9.1Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, D...
CVE-2026-30643CRITICAL9.8An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module u...
CVE-2026-20160CRITICAL9.8A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to...
CVE-2026-20093CRITICAL9.8A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unau...
CVE-2026-31027CRITICAL9.8TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste...
CVE-2026-34430CRITICAL9.6ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al...
CVE-2026-29014CRITICAL9.8MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at...
CVE-2026-4370CRITICAL10A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter...
CVE-2026-5257CRITICAL9.8A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of...
CVE-2026-5256CRITICAL9.8A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /m...
CVE-2026-5290CRITICAL9.6Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the...
CVE-2026-5289CRITICAL9.6Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now