2026 CVE Vulnerabilities

45,453 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2584CRITICAL9.3A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe...
CVE-2026-3422CRITICAL9.8U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote a...
CVE-2026-3413CRITICAL9.8A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the f...
CVE-2026-3000CRITICAL9.8IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r...
CVE-2026-2999CRITICAL9.8IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r...
CVE-2026-3411CRITICAL9.8A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is s...
CVE-2026-3410CRITICAL9.8A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-3406CRITICAL9.8A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of t...
CVE-2026-3400CRITICAL9.8A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionalit...
CVE-2026-3395CRITICAL9.8A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/p...
CVE-2026-28562CRITICAL9.8wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause ...
CVE-2026-28517CRITICAL9.8openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.ph...
CVE-2026-28411CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on...
CVE-2026-28408CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.p...
CVE-2026-28268CRITICAL9.8Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil...
CVE-2026-28231CRITICAL9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer o...
CVE-2026-27707CRITICAL9.8Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and ...
CVE-2026-2880CRITICAL9.1A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-sc...
CVE-2026-27755CRITICAL9.8SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th...
CVE-2026-27751CRITICAL9.8SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot...
CVE-2026-2293CRITICAL9.8A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fas...
CVE-2026-2750CRITICAL9.8Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tick...
CVE-2026-2751CRITICAL9.8Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web ...
CVE-2026-24352CRITICAL9.8PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa...
CVE-2026-21660CRITICAL9.8Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in F...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now