2026 CVE Vulnerabilities

46,868 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-1729CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th...
CVE-2026-26215CRITICAL9.3manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability th...
CVE-2026-20677CRITICAL9A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18...
CVE-2026-26021CRITICAL9.8set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability e...
CVE-2026-25994CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vu...
CVE-2026-25084CRITICAL9.8Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
CVE-2026-24789CRITICAL9.8An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
CVE-2026-2249CRITICAL9.8METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi...
CVE-2026-2248CRITICAL9.8METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi...
CVE-2026-1357CRITICAL9.8The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitr...
CVE-2026-26009CRITICAL9.9Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install...
CVE-2026-25993CRITICAL9.8EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application e...
CVE-2026-21531CRITICAL9.8Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
CVE-2026-1774CRITICAL9.8CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
CVE-2026-23906CRITICAL9.8Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0...
CVE-2026-2096CRITICAL9.8Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to...
CVE-2026-2095CRITICAL9.8Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to...
CVE-2026-0509CRITICAL9.6SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform backgrou...
CVE-2026-0488CRITICAL9.9An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function modul...
CVE-2026-25939CRITICAL9.1FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authori...
CVE-2026-25938CRITICAL9.8FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication b...
CVE-2026-25895CRITICAL9.8FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows ...
CVE-2026-25894CRITICAL9.8FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allo...
CVE-2026-25893CRITICAL9.8FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vuln...
CVE-2026-25923CRITICAL9.1my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now