2026 CVE Vulnerabilities

45,451 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22453CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects...
CVE-2026-22451CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This ...
CVE-2026-22417CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This is...
CVE-2026-22390CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b...
CVE-2026-3381CRITICAL9.8Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib incl...
CVE-2026-3257CRITICAL9.8UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl emb...
CVE-2026-2835CRITICAL9.1An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding ...
CVE-2026-2833CRITICAL9.1An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The i...
CVE-2026-29045CRITICAL9.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin...
CVE-2026-26002CRITICAL9.8Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4...
CVE-2026-29000CRITICAL9.3pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator w...
CVE-2026-3545CRITICAL9.6Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti...
CVE-2026-20131CRITICAL10A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2026-20079CRITICAL10A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti...
CVE-2026-28783CRITICAL9.1Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to...
CVE-2026-28697CRITICAL9.1Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can ...
CVE-2026-26478CRITICAL9.8A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attac...
CVE-2026-27446CRITICAL9.8Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unau...
CVE-2026-27441CRITICAL9.8SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS ...
CVE-2026-29119CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insec...
CVE-2026-28778CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/ins...
CVE-2026-28777CRITICAL9.8International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account....
CVE-2026-28776CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for th...
CVE-2026-28775CRITICAL9.8An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor...
CVE-2026-3266CRITICAL9.8Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now