2026 CVE Vulnerabilities

45,328 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-32731CRITICAL9.9ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ...
CVE-2026-31972CRITICAL9.8SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D...
CVE-2026-25873CRITICAL9.8OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows r...
CVE-2026-31967CRITICAL9.1HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-31966CRITICAL9.1HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-32633CRITICAL9.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/...
CVE-2026-32611CRITICAL9.1Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject...
CVE-2026-30704CRITICAL9.1The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hard...
CVE-2026-30703CRITICAL9.8A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX...
CVE-2026-30702CRITICAL9.8The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web manag...
CVE-2026-30701CRITICAL9.1The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure...
CVE-2026-29859CRITICAL9.8An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra...
CVE-2026-25449CRITICAL9.8Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affec...
CVE-2026-33265CRITICAL9In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
CVE-2026-30884CRITICAL9.6mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi...
CVE-2026-28500CRITICAL9.1Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc...
CVE-2026-22171CRITICAL9.1OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr...
CVE-2026-27459CRITICAL9.8pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u...
CVE-2026-3856CRITICAL9.1IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an...
CVE-2026-21994CRITICAL9.8Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P...
CVE-2026-32841CRITICAL9.2Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen...
CVE-2026-3207CRITICAL9.8Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
CVE-2026-4319CRITICAL9.8A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-32298CRITICAL9.1The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen...
CVE-2026-32297CRITICAL9.3The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now