2026 CVE Vulnerabilities

45,845 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-26974CRITICAL9.8Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo...
CVE-2026-27002CRITICAL9.8OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand...
CVE-2026-27476CRITICAL9.8RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins...
CVE-2026-27475CRITICAL9.2SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat...
CVE-2026-26057CRITICAL9.1Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious ...
CVE-2026-2409CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit...
CVE-2026-26339CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg...
CVE-2026-26338CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th...
CVE-2026-26030CRITICAL9.9Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to ...
CVE-2026-23549CRITICAL9.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2026-23542CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T...
CVE-2026-2731CRITICAL10Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow...
CVE-2026-2691CRITICAL9.8A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct...
CVE-2026-2690CRITICAL9.8A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown function...
CVE-2026-2689CRITICAL9.8A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /a...
CVE-2026-25242CRITICAL9.8Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints b...
CVE-2026-1994CRITICAL9.8The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ...
CVE-2026-1405CRITICAL9.8The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2026-0926CRITICAL9.8The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3....
CVE-2026-2686CRITICAL9.8A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file...
CVE-2026-2684CRITICAL9.8A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted ele...
CVE-2026-24126CRITICAL9.1Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input ...
CVE-2026-2682CRITICAL9.8A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an u...
CVE-2026-25548CRITICAL9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Co...
CVE-2026-27180CRITICAL9.8MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now