2026 CVE Vulnerabilities

46,856 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-26988CRITICAL9.1LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL ...
CVE-2026-26974CRITICAL9.8Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo...
CVE-2026-27002CRITICAL9.8OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand...
CVE-2026-27476CRITICAL9.8RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins...
CVE-2026-27475CRITICAL9.2SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat...
CVE-2026-26057CRITICAL9.1Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious ...
CVE-2026-2409CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit...
CVE-2026-26339CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg...
CVE-2026-26338CRITICAL9.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th...
CVE-2026-26030CRITICAL9.9Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to ...
CVE-2026-23549CRITICAL9.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2026-23542CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T...
CVE-2026-2731CRITICAL10Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow...
CVE-2026-2691CRITICAL9.8A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct...
CVE-2026-2690CRITICAL9.8A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown function...
CVE-2026-2689CRITICAL9.8A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /a...
CVE-2026-25242CRITICAL9.8Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints b...
CVE-2026-1994CRITICAL9.8The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ...
CVE-2026-1405CRITICAL9.8The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2026-0926CRITICAL9.8The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3....
CVE-2026-2686CRITICAL9.8A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file...
CVE-2026-2684CRITICAL9.8A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted ele...
CVE-2026-24126CRITICAL9.1Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input ...
CVE-2026-2682CRITICAL9.8A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an u...
CVE-2026-25548CRITICAL9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now