2026 CVE Vulnerabilities

46,924 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2114CRITICAL9.8A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of t...
CVE-2026-25858CRITICAL9.3macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workf...
CVE-2026-25560CRITICAL9.8WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna...
CVE-2026-2113CRITICAL9.8A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library...
CVE-2026-2090CRITICAL9.8A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown process...
CVE-2026-2089CRITICAL9.8A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of t...
CVE-2026-2088CRITICAL9.8A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the f...
CVE-2026-2087CRITICAL9.8A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functiona...
CVE-2026-2083CRITICAL9.8A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the...
CVE-2026-2073CRITICAL9.8A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil...
CVE-2026-25804CRITICAL9.1Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's...
CVE-2026-25803CRITICAL9.83DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an admi...
CVE-2026-25763CRITICAL9.9OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary ...
CVE-2026-25544CRITICAL9.8Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fi...
CVE-2026-1731CRITICAL9.8BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-auth...
CVE-2026-1727CRITICAL9.1The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable ...
CVE-2026-25632CRITICAL10EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis...
CVE-2026-25592CRITICAL9.9Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an ...
CVE-2026-25643CRITICAL9.1Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critic...
CVE-2026-25641CRITICAL9SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch...
CVE-2026-25587CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtain...
CVE-2026-25586CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty ...
CVE-2026-25520CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.val...
CVE-2026-1709CRITICAL9.8A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer S...
CVE-2026-25753CRITICAL9.8PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now