2026 CVE Vulnerabilities

45,497 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27847CRITICAL9.8Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connec...
CVE-2026-27702CRITICAL9Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un...
CVE-2026-3187CRITICAL9.8A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f...
CVE-2026-27699CRITICAL9.8The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2...
CVE-2026-2624CRITICAL9.8Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Gene...
CVE-2026-0704CRITICAL9.1In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API ...
CVE-2026-3164CRITICAL9.8A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the fil...
CVE-2026-3153CRITICAL9.8A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the fi...
CVE-2026-3152CRITICAL9.8A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the f...
CVE-2026-3151CRITICAL9.8A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of t...
CVE-2026-25785CRITICAL9.8Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlie...
CVE-2026-3148CRITICAL9.8A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown funct...
CVE-2026-27744CRITICAL9.8The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the fo...
CVE-2026-27743CRITICAL9.8The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the refer...
CVE-2026-27641CRITICAL9.8Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versio...
CVE-2026-27637CRITICAL9.8FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's...
CVE-2026-27597CRITICAL10Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possibl...
CVE-2026-27626CRITICAL9.9OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, Oliv...
CVE-2026-27607CRITICAL9.1RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS d...
CVE-2026-27606CRITICAL9.8Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (sp...
CVE-2026-3135CRITICAL9.8A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of t...
CVE-2026-3134CRITICAL9.8A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function...
CVE-2026-3133CRITICAL9.8A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processin...
CVE-2026-22553CRITICAL9.8All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web in...
CVE-2026-21410CRITICAL9.8InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now