2026 CVE Vulnerabilities

45,376 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22171CRITICAL9.1OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr...
CVE-2026-27459CRITICAL9.8pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u...
CVE-2026-3856CRITICAL9.1IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an...
CVE-2026-21994CRITICAL9.8Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P...
CVE-2026-32841CRITICAL9.2Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen...
CVE-2026-3207CRITICAL9.8Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
CVE-2026-4319CRITICAL9.8A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-32298CRITICAL9.1The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen...
CVE-2026-32297CRITICAL9.3The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ...
CVE-2026-32295CRITICAL9.3JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
CVE-2026-32292CRITICAL9.3The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede...
CVE-2026-25769CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1...
CVE-2026-25534CRITICAL9.1### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri...
CVE-2026-3564CRITICAL9A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ...
CVE-2026-4312CRITICAL9.8GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remot...
CVE-2026-4177CRITICAL9.1YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap ...
CVE-2026-32267CRITICAL9.8Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R...
CVE-2026-28430CRITICAL9.8Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera...
CVE-2026-4254CRITICAL9.8A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of th...
CVE-2026-27962CRITICAL9.1Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injectio...
CVE-2026-23489CRITICAL9.1Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possi...
CVE-2026-4252CRITICAL9.8A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the com...
CVE-2026-4228CRITICAL9.8A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wi...
CVE-2026-4226CRITICAL9.8A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /...
CVE-2026-4223CRITICAL9.8A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now