2026 CVE Vulnerabilities

45,220 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25031CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This iss...
CVE-2026-25030CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affe...
CVE-2026-25029CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KI...
CVE-2026-24993CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced...
CVE-2026-24989CRITICAL9.8Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.Thi...
CVE-2026-24971CRITICAL9.8Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issu...
CVE-2026-24968CRITICAL9.8Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue aff...
CVE-2026-24378CRITICAL9.8Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Obje...
CVE-2026-22507CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affec...
CVE-2026-22500CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Inj...
CVE-2026-22484CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Co...
CVE-2026-26833CRITICAL9.8thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun...
CVE-2026-26832CRITICAL9.8node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, t...
CVE-2026-26831CRITICAL9.8textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr...
CVE-2026-26830CRITICAL9.8pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGe...
CVE-2026-4784CRITICAL9.8A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /chec...
CVE-2026-28858CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote...
CVE-2026-28827CRITICAL9.3A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2026-20688CRITICAL9.3A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Seq...
CVE-2026-24159CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit o...
CVE-2026-24157CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution...
CVE-2026-33511CRITICAL9.8pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97...
CVE-2026-33322CRITICAL9.8MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-...
CVE-2026-33768CRITICAL9.1Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head...
CVE-2026-33409CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now