2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-44100CRITICAL9.4The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di...
CVE-2026-44092CRITICAL9.1An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not vali...
CVE-2026-44091CRITICAL9.1An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configura...
CVE-2026-44090CRITICAL9.8Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected fr...
CVE-2026-58066CRITICAL9.8Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML ...
CVE-2026-58046CRITICAL9.9Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL inject...
CVE-2026-14602CRITICAL9The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al...
CVE-2026-16610CRITICAL9.8The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
CVE-2026-48449CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-18015CRITICAL9.6Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potenti...
CVE-2026-18002CRITICAL9.6Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attac...
CVE-2026-17991CRITICAL9.6Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h...
CVE-2026-17990CRITICAL9.6Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker...
CVE-2026-17987CRITICAL9.6Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote att...
CVE-2026-17947CRITICAL9.6Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a ...
CVE-2026-17940CRITICAL9.6Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allo...
CVE-2026-17924CRITICAL9.6Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer...
CVE-2026-17865CRITICAL9.6Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had ...
CVE-2026-17856CRITICAL9.6Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had...
CVE-2026-17855CRITICAL9.6Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the render...
CVE-2026-17848CRITICAL9.6Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sa...
CVE-2026-17847CRITICAL9.6Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to...
CVE-2026-17837CRITICAL9.6Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker...
CVE-2026-17834CRITICAL9.6Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke...
CVE-2026-17832CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now