2026 CVE Vulnerabilities

45,125 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-5033CRITICAL9.8A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi...
CVE-2026-5030CRITICAL9.8A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos...
CVE-2026-5020CRITICAL9.8A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNotice...
CVE-2026-4851CRITICAL9.8GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine...
CVE-2026-5019CRITICAL9.8A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability...
CVE-2026-5018CRITICAL9.8A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the fil...
CVE-2026-5017CRITICAL9.8A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of t...
CVE-2026-3256CRITICAL9.8HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults ...
CVE-2026-33994CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39...
CVE-2026-33993CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t...
CVE-2026-33976CRITICAL9.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We...
CVE-2026-33943CRITICAL9.8Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro...
CVE-2026-33937CRITICAL9.8Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handleb...
CVE-2026-33896CRITICAL9.1Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33879CRITICAL9.8Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation...
CVE-2026-33875CRITICAL9.3Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 ar...
CVE-2026-33873CRITICAL9.9Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assis...
CVE-2026-34475CRITICAL9.8Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR...
CVE-2026-34205CRITICAL9.6Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f...
CVE-2026-33765CRITICAL9.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33654CRITICAL9.8nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema...
CVE-2026-34387CRITICAL9.8Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software ...
CVE-2026-34374CRITICAL9.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met...
CVE-2026-4965CRITICAL9.8A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu...
CVE-2026-4963CRITICAL10A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now