2026 CVE Vulnerabilities

45,845 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27179CRITICAL9.8MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. Th...
CVE-2026-27175CRITICAL9.8MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param...
CVE-2026-27174CRITICAL9.8MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console fea...
CVE-2026-0573CRITICAL9An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects t...
CVE-2026-2329CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A ...
CVE-2026-2654CRITICAL9.8A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of ...
CVE-2026-1435CRITICAL9.8Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of s...
CVE-2026-1670CRITICAL9.8The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotel...
CVE-2026-22769CRITICAL10Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. Thi...
CVE-2026-23647CRITICAL9.8Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that...
CVE-2026-2616CRITICAL9.8A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the compo...
CVE-2026-22208CRITICAL9.6OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil...
CVE-2026-26220CRITICAL9.3LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) d...
CVE-2026-2439CRITICAL9.8Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id fun...
CVE-2026-2564CRITICAL9.2A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an u...
CVE-2026-2577CRITICAL10The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by ...
CVE-2026-2550CRITICAL9.8A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file ...
CVE-2026-2532CRITICAL9.8A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the fil...
CVE-2026-2529CRITICAL9.8A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteM...
CVE-2026-2528CRITICAL9.8A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Dele...
CVE-2026-2527CRITICAL9.8A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bi...
CVE-2026-2522CRITICAL9.8A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/...
CVE-2026-2521CRITICAL9.8A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re...
CVE-2026-26369CRITICAL9.8eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization c...
CVE-2026-26366CRITICAL9.8eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now