2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-67305CRITICAL9.4FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when...
CVE-2026-67294CRITICAL9.3FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si...
CVE-2026-67293CRITICAL9.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ...
CVE-2026-67292CRITICAL9.3FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor...
CVE-2026-67289CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll...
CVE-2026-66402CRITICAL9.8FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ...
CVE-2026-15964CRITICAL9.8The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese...
CVE-2026-13596CRITICAL9.1The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied paramete...
CVE-2026-3141CRITICAL9.1The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec...
CVE-2026-68771CRITICAL9.8ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic...
CVE-2026-52134CRITICAL9.8An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au...
CVE-2026-68770CRITICAL9.8sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code e...
CVE-2026-51785CRITICAL9.8An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted req...
CVE-2026-38713CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...
CVE-2026-38708CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...
CVE-2026-38711CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...
CVE-2026-54725CRITICAL9.6vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1...
CVE-2026-21662CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic...
CVE-2026-67822CRITICAL9.8Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu...
CVE-2026-58048CRITICAL9.4Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVE-2026-52855CRITICAL9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{...
CVE-2026-17566CRITICAL9.9pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in...
CVE-2026-17351CRITICAL9The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu...
CVE-2026-17349CRITICAL9.6/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of ...
CVE-2026-16504CRITICAL9.8Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now