2026 CVE Vulnerabilities

46,941 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25139CRITICAL9.1RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2026-22247CRITICAL9.1GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can ...
CVE-2026-25115CRITICAL9.9n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allo...
CVE-2026-25053CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git nod...
CVE-2026-25052CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file ac...
CVE-2026-25049CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with per...
CVE-2026-1813CRITICAL9.8A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/...
CVE-2026-1633CRITICAL10The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authe...
CVE-2026-1812CRITICAL9.8A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the fi...
CVE-2026-1632CRITICAL9.3MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, ...
CVE-2026-25150CRITICAL10Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists ...
CVE-2026-1341CRITICAL9.3Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
CVE-2026-25241CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL...
CVE-2026-25240CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner...
CVE-2026-25238CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner...
CVE-2026-25237CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() ...
CVE-2026-25236CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk e...
CVE-2026-25234CRITICAL9.8PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner...
CVE-2026-25233CRITICAL9.1PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadm...
CVE-2026-1568CRITICAL9.6Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c...
CVE-2026-1432CRITICAL9.3SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vuln...
CVE-2026-24465CRITICAL9.8Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead ...
CVE-2026-24936CRITICAL9.8When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerab...
CVE-2026-25142CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ whic...
CVE-2026-25137CRITICAL9.1The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now