2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-47705CRITICAL9.6TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. ...
CVE-2026-27302CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-71384CRITICAL9.6is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul...
CVE-2026-70306CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-65791CRITICAL9.8Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ...
CVE-2026-62893CRITICAL9.8Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62878CRITICAL9.8Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-62815CRITICAL9.8Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-59124CRITICAL9.8Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to ...
CVE-2026-50516CRITICAL9.4Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-48362CRITICAL10ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ...
CVE-2026-12571CRITICAL9.8An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
CVE-2026-73080CRITICAL9.3SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re...
CVE-2026-73069CRITICAL9.1Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad...
CVE-2026-72920CRITICAL9.8SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s...
CVE-2026-47702CRITICAL9.1TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu...
CVE-2026-17061CRITICAL10A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2...
CVE-2026-48056CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro...
CVE-2026-48046CRITICAL9.3Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai...
CVE-2026-46670CRITICAL9.8YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp...
CVE-2026-72785CRITICAL9.3Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only ...
CVE-2026-72748CRITICAL9.1AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a...
CVE-2026-58115CRITICAL10A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In...
CVE-2026-18972CRITICAL9.6An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M...
CVE-2026-72603CRITICAL9.9An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now