2026 CVE Vulnerabilities

45,193 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-33640CRITICAL9.8Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n...
CVE-2026-30458CRITICAL9.1An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt...
CVE-2026-30457CRITICAL9.8An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via ...
CVE-2026-26213CRITICAL9.8thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner...
CVE-2026-33494CRITICAL10ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2026-27816CRITICAL9.1EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_tra...
CVE-2026-27815CRITICAL9.1EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup cop...
CVE-2026-33396CRITICAL9.9OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica...
CVE-2026-4809CRITICAL9.8plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac...
CVE-2026-4850CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the f...
CVE-2026-33942CRITICAL9.8Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's un...
CVE-2026-33183CRITICAL9.1Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names...
CVE-2026-30975CRITICAL9.8Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affect...
CVE-2026-33749CRITICAL9n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated use...
CVE-2026-32573CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test...
CVE-2026-32539CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi...
CVE-2026-32536CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-download...
CVE-2026-32525CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder all...
CVE-2026-32524CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web S...
CVE-2026-32523CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious...
CVE-2026-32520CRITICAL9.8Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalati...
CVE-2026-32519CRITICAL9Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affect...
CVE-2026-32512CRITICAL9.8Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows...
CVE-2026-32502CRITICAL9.8Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object ...
CVE-2026-32499CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatB...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now