2026 CVE Vulnerabilities

45,138 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-29014CRITICAL9.8MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at...
CVE-2026-4370CRITICAL10A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter...
CVE-2026-5257CRITICAL9.8A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of...
CVE-2026-5256CRITICAL9.8A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /m...
CVE-2026-5290CRITICAL9.6Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the...
CVE-2026-5289CRITICAL9.6Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the ...
CVE-2026-5288CRITICAL9.6Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi...
CVE-2026-4374CRITICAL9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service...
CVE-2026-34449CRITICAL9.6SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Ex...
CVE-2026-34448CRITICAL9SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in a...
CVE-2026-34400CRITICAL9.8Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection vi...
CVE-2026-1579CRITICAL9.8The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s...
CVE-2026-4800CRITICAL9.8Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variabl...
CVE-2026-30285CRITICAL9.8An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic...
CVE-2026-3356CRITICAL9.3The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access ...
CVE-2026-30286CRITICAL9.8An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite ...
CVE-2026-30283CRITICAL9.8An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to o...
CVE-2026-30282CRITICAL9An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri...
CVE-2026-30278CRITICAL9.8An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica...
CVE-2026-34361CRITICAL9.3HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-34359CRITICAL9.1HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-24164CRITICAL9.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo...
CVE-2026-24148CRITICAL9.4NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co...
CVE-2026-34243CRITICAL9.8wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3...
CVE-2026-34235CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-boun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now