2026 CVE Vulnerabilities

45,152 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-33654CRITICAL9.8nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema...
CVE-2026-34387CRITICAL9.8Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software ...
CVE-2026-34374CRITICAL9.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met...
CVE-2026-4965CRITICAL9.8A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu...
CVE-2026-4963CRITICAL10A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu...
CVE-2026-33770CRITICAL9.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method ...
CVE-2026-28369CRITICAL9.1A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more...
CVE-2026-28368CRITICAL9.1A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ...
CVE-2026-28367CRITICAL9.1A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter...
CVE-2026-30533CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ...
CVE-2026-30532CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi...
CVE-2026-30530CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30302CRITICAL10The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli...
CVE-2026-30304CRITICAL9.6In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al...
CVE-2026-30303CRITICAL9.8The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se...
CVE-2026-27876CRITICAL9.1A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac...
CVE-2026-1496CRITICAL9.3Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ...
CVE-2026-4622CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4620CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4619CRITICAL9.8Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
CVE-2026-25101CRITICAL9.8Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft...
CVE-2026-33280CRITICAL9.8Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr...
CVE-2026-32669CRITICAL9.8Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c...
CVE-2026-27650CRITICAL9.8OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit...
CVE-2026-22738CRITICAL9.8In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now