2026 CVE Vulnerabilities

45,444 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-30965CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-0120CRITICAL9.8In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execu...
CVE-2026-0116CRITICAL9.8In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2026-0114CRITICAL9.8In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execu...
CVE-2026-0113CRITICAL9.8In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This...
CVE-2026-0111CRITICAL9.8In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This...
CVE-2026-0110CRITICAL9.8In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote ...
CVE-2026-29793CRITICAL9.8Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to...
CVE-2026-29792CRITICAL9.8Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to ...
CVE-2026-28292CRITICAL9.8`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through ...
CVE-2026-3843CRITICAL9.8Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-8...
CVE-2026-30970CRITICAL9.1Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I...
CVE-2026-30969CRITICAL9.1Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I...
CVE-2026-30968CRITICAL9.8Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I...
CVE-2026-30960CRITICAL9.4rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical...
CVE-2026-30957CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allo...
CVE-2026-30956CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass ...
CVE-2026-30930CRITICAL9.8Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module construct...
CVE-2026-26105CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-23240CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() ...
CVE-2026-30921CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allo...
CVE-2026-30887CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members ...
CVE-2026-30869CRITICAL9.8SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoin...
CVE-2026-30862CRITICAL9Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulne...
CVE-2026-27685CRITICAL9.1SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now