2026 CVE Vulnerabilities

45,232 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-4698CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115...
CVE-2026-4696CRITICAL9.8Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,...
CVE-2026-4692CRITICAL10Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,...
CVE-2026-4691CRITICAL9.8Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 11...
CVE-2026-4689CRITICAL10Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fix...
CVE-2026-4688CRITICAL10Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 14...
CVE-2026-33475CRITICAL9.1Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection...
CVE-2026-33309CRITICAL9.9Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypas...
CVE-2026-4755CRITICAL9.8CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
CVE-2026-4753CRITICAL9.1Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
CVE-2026-4750CRITICAL9.1Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.
CVE-2026-33854CRITICAL9.8Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before ...
CVE-2026-4746CRITICAL10Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is assoc...
CVE-2026-4745CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modul...
CVE-2026-4283CRITICAL9.1The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, ...
CVE-2026-4744CRITICAL9.3Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associ...
CVE-2026-4739CRITICAL9.4Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modul...
CVE-2026-4738CRITICAL9.4Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/...
CVE-2026-4734CRITICAL9.4Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt...
CVE-2026-4001CRITICAL9.8The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
CVE-2026-33286CRITICAL9.1Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior t...
CVE-2026-33211CRITICAL9.6Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-33202CRITICAL9.1Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33195CRITICAL9.8Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-4681CRITICAL9.3A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now