2026 CVE Vulnerabilities

46,928 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25752CRITICAL9.1FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA ...
CVE-2026-2060CRITICAL9.8A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is a...
CVE-2026-25725CRITICAL10Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to p...
CVE-2026-25722CRITICAL9.1Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory change...
CVE-2026-2059CRITICAL9.8A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown fun...
CVE-2026-2058CRITICAL9.8A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This im...
CVE-2026-2057CRITICAL9.8A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown func...
CVE-2026-2018CRITICAL9.8A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/s...
CVE-2026-2017CRITICAL9.8A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurity...
CVE-2026-2014CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of t...
CVE-2026-2013CRITICAL9.8A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the fi...
CVE-2026-2012CRITICAL9.8A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown functio...
CVE-2026-2011CRITICAL9.8A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of ...
CVE-2026-21643CRITICAL9.8An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC...
CVE-2026-24302CRITICAL9.8Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-24300CRITICAL9.8Azure Front Door Elevation of Privilege Vulnerability
CVE-2026-1963CRITICAL9.8A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the...
CVE-2026-1962CRITICAL9.8A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attac...
CVE-2026-0106CRITICAL9.3In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to l...
CVE-2026-23796CRITICAL9.8Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the sa...
CVE-2026-25547CRITICAL9.2@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-ex...
CVE-2026-25526CRITICAL9.8JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to ver...
CVE-2026-25519CRITICAL9.8OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and electio...
CVE-2026-25505CRITICAL9.8Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardc...
CVE-2026-25481CRITICAL9.6Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a byp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now