2026 CVE Vulnerabilities

45,788 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2952CRITICAL9.8A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the...
CVE-2026-2944CRITICAL9.8A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function s...
CVE-2026-2912CRITICAL9.8A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /syst...
CVE-2026-2894CRITICAL9.1A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of ...
CVE-2026-2867CRITICAL9.8A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the fil...
CVE-2026-27574CRITICAL9.9OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript mon...
CVE-2026-2865CRITICAL9.8A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of t...
CVE-2026-27471CRITICAL9.1ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 1...
CVE-2026-27211CRITICAL10Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary...
CVE-2026-27197CRITICAL9.1Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a criti...
CVE-2026-27194CRITICAL9.8D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution thro...
CVE-2026-27168CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. A...
CVE-2026-2635CRITICAL9.8MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass...
CVE-2026-2039CRITICAL9.8GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote atta...
CVE-2026-2038CRITICAL9.8GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attac...
CVE-2026-27112CRITICAL9.9Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the b...
CVE-2026-27190CRITICAL9.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in D...
CVE-2026-25896CRITICAL9.3fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-2848CRITICAL9.8A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unkn...
CVE-2026-2333CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I...
CVE-2026-26747CRITICAL9.1A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro...
CVE-2026-26725CRITICAL9.8An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate ...
CVE-2026-26722CRITICAL9.4An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privi...
CVE-2026-26093CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I...
CVE-2026-25715CRITICAL9.8The web management interface of the device allows the administrator username and password to be set to blank values. On...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now