2026 CVE Vulnerabilities

45,460 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27494CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user...
CVE-2026-27493CRITICAL9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres...
CVE-2026-27575CRITICAL9.1Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to ...
CVE-2026-27148CRITICAL9.6Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23...
CVE-2026-25997CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` re...
CVE-2026-25959CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` pas...
CVE-2026-25955CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface...
CVE-2026-25953CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface...
CVE-2026-25952CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` deref...
CVE-2026-0542CRITICAL9.2ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This ...
CVE-2026-22720CRITICAL9VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create...
CVE-2026-27739CRITICAL9.2The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17...
CVE-2026-21902CRITICAL9.8An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juni...
CVE-2026-27849CRITICAL9.8Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP...
CVE-2026-27727CRITICAL9.8mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI f...
CVE-2026-20129CRITICAL9.8A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote a...
CVE-2026-20127CRITICAL10A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalys...
CVE-2026-27848CRITICAL9.8Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection...
CVE-2026-27847CRITICAL9.8Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connec...
CVE-2026-27702CRITICAL9Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un...
CVE-2026-3187CRITICAL9.8A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f...
CVE-2026-27699CRITICAL9.8The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2...
CVE-2026-2624CRITICAL9.8Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Gene...
CVE-2026-0704CRITICAL9.1In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API ...
CVE-2026-3164CRITICAL9.8A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now