2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-16503CRITICAL9.1Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces ...
CVE-2026-17561CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons...
CVE-2026-18452CRITICAL10DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att...
CVE-2026-14919CRITICAL9.8The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be...
CVE-2026-14483CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver...
CVE-2026-63223CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i...
CVE-2026-63221CRITICAL9.4CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v...
CVE-2026-43830CRITICAL9.8Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-14537CRITICAL9.8Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0...
CVE-2026-66421CRITICAL9.3OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-38709CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...
CVE-2026-68503CRITICAL9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def...
CVE-2026-68502CRITICAL9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2....
CVE-2026-66803CRITICAL10Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-66418CRITICAL9.3OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack...
CVE-2026-52539CRITICAL9.1Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se...
CVE-2026-35847CRITICAL9.8An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the Chec...
CVE-2026-67594CRITICAL9.8Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attac...
CVE-2026-67208CRITICAL9.8Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to exec...
CVE-2026-66756CRITICAL9.8Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 ...
CVE-2026-12946CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the i...
CVE-2026-66066CRITICAL9.5Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3....
CVE-2026-48499CRITICAL9.3Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code...
CVE-2026-15976CRITICAL9.8SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi...
CVE-2026-15971CRITICAL9.8SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now