2026 CVE Vulnerabilities

46,870 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25881CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to m...
CVE-2026-25875CRITICAL9.8PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorizatio...
CVE-2026-25814CRITICAL9.8PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query ...
CVE-2026-25811CRITICAL9.1PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derive...
CVE-2026-25876CRITICAL9.1PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes...
CVE-2026-25810CRITICAL9.1PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes...
CVE-2026-25809CRITICAL9.8PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation en...
CVE-2026-25057CRITICAL9.1MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able ...
CVE-2026-24679CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied...
CVE-2026-24677CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts serv...
CVE-2026-25848CRITICAL9.8In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
CVE-2026-2225CRITICAL9.8A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admi...
CVE-2026-2234CRITICAL9.3C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to rea...
CVE-2026-2223CRITICAL9.8A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some u...
CVE-2026-22906CRITICAL9.8User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining ...
CVE-2026-22904CRITICAL9.8Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attack...
CVE-2026-22903CRITICAL9.8An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can ...
CVE-2026-2221CRITICAL9.8A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the ...
CVE-2026-2220CRITICAL9.8A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file...
CVE-2026-1868CRITICAL9.9GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions ...
CVE-2026-2217CRITICAL9.8A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of th...
CVE-2026-1615CRITICAL9.8Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-s...
CVE-2026-2212CRITICAL9.8A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown func...
CVE-2026-2211CRITICAL9.8A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Admi...
CVE-2026-2199CRITICAL9.8A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown func...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now