2026 CVE Vulnerabilities

45,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-33211CRITICAL9.6Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-33202CRITICAL9.1Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33195CRITICAL9.8Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-4681CRITICAL9.3A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili...
CVE-2026-32913CRITICAL9.1OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom...
CVE-2026-3055CRITICAL9.8Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory ove...
CVE-2026-30849CRITICAL9.8Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family database...
CVE-2026-2298CRITICAL9.4Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing...
CVE-2026-33716CRITICAL9.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e...
CVE-2026-0898CRITICAL9An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom...
CVE-2026-4404CRITICAL9.4Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password ...
CVE-2026-33478CRITICAL10WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's...
CVE-2026-33352CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exis...
CVE-2026-33351CRITICAL9.1WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability ...
CVE-2026-33297CRITICAL9.1WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz...
CVE-2026-31851CRITICAL9.8Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec...
CVE-2026-31848CRITICAL9.8Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which conta...
CVE-2026-4585CRITICAL9.8A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects u...
CVE-2026-32968CRITICAL9.8Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exp...
CVE-2026-4581CRITICAL9.8A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /...
CVE-2026-4580CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ...
CVE-2026-4579CRITICAL9.8A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ...
CVE-2026-3587CRITICAL10An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l...
CVE-2026-4601CRITICAL9.1Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig...
CVE-2026-4600CRITICAL9.1Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now