2026 CVE Vulnerabilities

45,307 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-30836CRITICAL10Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ...
CVE-2026-27953CRITICAL9.8ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the...
CVE-2026-26138CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26137CRITICAL9.9Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw...
CVE-2026-23658CRITICAL9.8Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-32238CRITICAL9.1OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-3548CRITICAL9.8Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over...
CVE-2026-30694CRITICAL9.8An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone...
CVE-2026-32867CRITICAL9.8OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ...
CVE-2026-32865CRITICAL9.8OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque...
CVE-2026-30402CRITICAL9.8An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi...
CVE-2026-2369CRITICAL9.1A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour...
CVE-2026-22557CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App...
CVE-2026-27067CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa...
CVE-2026-27065CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27542CRITICAL9.8Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh...
CVE-2026-27540CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu...
CVE-2026-27413CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile...
CVE-2026-32737CRITICAL10Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function...
CVE-2026-32731CRITICAL9.9ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ...
CVE-2026-31972CRITICAL9.8SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D...
CVE-2026-25873CRITICAL9.8OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows r...
CVE-2026-31967CRITICAL9.1HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-31966CRITICAL9.1HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-32633CRITICAL9.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now