2026 CVE Vulnerabilities

45,436 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-1525CRITICAL9.8Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Co...
CVE-2026-32232CRITICAL9.8ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Valid...
CVE-2026-26793CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. Thi...
CVE-2026-28256CRITICAL9.8A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge coul...
CVE-2026-28255CRITICAL9.8A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attack...
CVE-2026-28252CRITICAL9.8A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge co...
CVE-2026-26795CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the ...
CVE-2026-26792CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade func...
CVE-2026-26791CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in...
CVE-2026-28792CRITICAL9.6Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS con...
CVE-2026-21708CRITICAL9.9A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
CVE-2026-28384CRITICAL9.4An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged u...
CVE-2026-21671CRITICAL9.1A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE)...
CVE-2026-21669CRITICAL9.9A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-3060CRITICAL9.8SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disagg...
CVE-2026-3059CRITICAL9.8SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, whi...
CVE-2026-4014CRITICAL9.8A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the...
CVE-2026-3981CRITICAL9.8A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the f...
CVE-2026-3980CRITICAL9.8A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of...
CVE-2026-3916CRITICAL9.6Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perfor...
CVE-2026-32136CRITICAL9.8AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote atta...
CVE-2026-32133CRITICAL9.12FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0...
CVE-2026-27591CRITICAL9.9Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1....
CVE-2026-32118CRITICAL9OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-31976CRITICAL9.8xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now