2026 CVE Vulnerabilities

45,829 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25896CRITICAL9.3fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-2848CRITICAL9.8A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unkn...
CVE-2026-2333CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I...
CVE-2026-26747CRITICAL9.1A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro...
CVE-2026-26725CRITICAL9.8An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate ...
CVE-2026-26722CRITICAL9.4An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privi...
CVE-2026-26093CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I...
CVE-2026-25715CRITICAL9.8The web management interface of the device allows the administrator username and password to be set to blank values. On...
CVE-2026-24956CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download ...
CVE-2026-22384CRITICAL9.8Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injecti...
CVE-2026-21627CRITICAL9.5The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax...
CVE-2026-26988CRITICAL9.1LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL ...
CVE-2026-26974CRITICAL9.8Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo...
CVE-2026-27002CRITICAL9.8OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand...
CVE-2026-27476CRITICAL9.8RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins...
CVE-2026-27475CRITICAL9.2SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat...
CVE-2026-26057CRITICAL9.1Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious ...
CVE-2026-2409CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit...
CVE-2026-26339CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg...
CVE-2026-26338CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th...
CVE-2026-26030CRITICAL9.9Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to ...
CVE-2026-23549CRITICAL9.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2026-23542CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T...
CVE-2026-2731CRITICAL10Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow...
CVE-2026-2691CRITICAL9.8A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now