2026 CVE Vulnerabilities

45,452 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27971CRITICAL9.8Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization ...
CVE-2026-26279CRITICAL9.1Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins...
CVE-2026-3224CRITICAL9.8Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear...
CVE-2026-3204CRITICAL9.8Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers...
CVE-2026-3130CRITICAL9.8Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker...
CVE-2026-2590CRITICAL9.8Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions...
CVE-2026-27012CRITICAL9.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri...
CVE-2026-24898CRITICAL9.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0,...
CVE-2026-24848CRITICAL9.9OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and ea...
CVE-2026-3485CRITICAL9.8A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This...
CVE-2026-3136CRITICAL9.8An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allow...
CVE-2026-24103CRITICAL9.8A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
CVE-2026-22891CRITICAL9.8A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig...
CVE-2026-22886CRITICAL9.8OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product...
CVE-2026-1492CRITICAL9.8The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2026-2628CRITICAL9.8The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass...
CVE-2026-26713CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
CVE-2026-26712CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
CVE-2026-26711CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
CVE-2026-26710CRITICAL9.8code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
CVE-2026-26709CRITICAL9.8code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
CVE-2026-0006CRITICAL9.8In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead t...
CVE-2026-26707CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
CVE-2026-26706CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
CVE-2026-26705CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now