2026 CVE Vulnerabilities

45,440 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-31957CRITICAL10Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelbl...
CVE-2026-31900CRITICAL9.8Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo...
CVE-2026-31896CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exist...
CVE-2026-27703CRITICAL9.8RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2026-27478CRITICAL9.1Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu...
CVE-2026-31881CRITICAL9.8Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin...
CVE-2026-31877CRITICAL9.8Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce...
CVE-2026-31874CRITICAL9.8Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the ...
CVE-2026-31975CRITICAL9.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31871CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31856CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection ...
CVE-2026-31852CRITICAL9.8Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulner...
CVE-2026-31840CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-1524CRITICAL9.8An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised...
CVE-2026-30741CRITICAL9.8A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary c...
CVE-2026-30903CRITICAL9.8External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth...
CVE-2026-3944CRITICAL9.8A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code...
CVE-2026-3826CRITICAL9.8IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to exe...
CVE-2026-2631CRITICAL9.8The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows a...
CVE-2026-27842CRITICAL9.8Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication an...
CVE-2026-24448CRITICAL9.8Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administr...
CVE-2026-29515CRITICAL9.8MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all...
CVE-2026-23813CRITICAL9.8A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allo...
CVE-2026-31800CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30966CRITICAL10Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now