2026 CVE Vulnerabilities

45,191 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-30533CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ...
CVE-2026-30532CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi...
CVE-2026-30530CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30302CRITICAL10The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli...
CVE-2026-30304CRITICAL9.6In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al...
CVE-2026-30303CRITICAL9.8The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se...
CVE-2026-27876CRITICAL9.1A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac...
CVE-2026-1496CRITICAL9.3Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ...
CVE-2026-4622CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4620CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4619CRITICAL9.8Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
CVE-2026-25101CRITICAL9.8Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft...
CVE-2026-33280CRITICAL9.8Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr...
CVE-2026-32669CRITICAL9.8Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c...
CVE-2026-27650CRITICAL9.8OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit...
CVE-2026-22738CRITICAL9.8In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ...
CVE-2026-4908CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ...
CVE-2026-33890CRITICAL9.8MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att...
CVE-2026-33747CRITICAL9.8BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P...
CVE-2026-33729CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2026-33728CRITICAL9.8dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI ins...
CVE-2026-33718CRITICAL9.9OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in ...
CVE-2026-33701CRITICAL9.8OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I...
CVE-2026-33945CRITICAL9.6Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to system...
CVE-2026-34352CRITICAL9.8In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now