2026 CVE Vulnerabilities

45,436 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-32640CRITICAL9.8SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu...
CVE-2026-32635CRITICAL9Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-32626CRITICAL9.6AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32621CRITICAL9.9Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11...
CVE-2026-20998CRITICAL9.8Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20997CRITICAL9.8Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to p...
CVE-2026-3891CRITICAL9.8The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and...
CVE-2026-32746CRITICAL9.8telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ...
CVE-2026-32367CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog al...
CVE-2026-32306CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API acc...
CVE-2026-32304CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat...
CVE-2026-32301CRITICAL9.3Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Sid...
CVE-2026-31897CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free...
CVE-2026-31885CRITICAL9.4FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-A...
CVE-2026-31883CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM an...
CVE-2026-31806CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function proce...
CVE-2026-26954CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, whic...
CVE-2026-25823CRITICAL9.8HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25818CRITICAL9.1HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-23941CRITICAL9.4Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module)...
CVE-2026-22192CRITICAL9.9Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated att...
CVE-2026-1668CRITICAL9.8The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out...
CVE-2026-3611CRITICAL10The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-...
CVE-2026-32260CRITICAL9.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exist...
CVE-2026-32248CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now