2026 CVE Vulnerabilities

46,942 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-24471CRITICAL9.3continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote serve...
CVE-2026-23997CRITICAL9FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro...
CVE-2026-22778CRITICAL9.8vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid i...
CVE-2026-20418CRITICAL9.8In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation o...
CVE-2026-20407CRITICAL9.3In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local ...
CVE-2026-25202CRITICAL9.8The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo...
CVE-2026-25200CRITICAL9.8A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto...
CVE-2026-1740CRITICAL9.8A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file ...
CVE-2026-25069CRITICAL9.3SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log ...
CVE-2026-25141CRITICAL9.8Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starti...
CVE-2026-25130CRITICAL9.6Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI...
CVE-2026-1723CRITICAL9.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60...
CVE-2026-1701CRITICAL9.8A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown...
CVE-2026-1688CRITICAL9.8A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an u...
CVE-2026-24729CRITICAL10An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker ver...
CVE-2026-24728CRITICAL9.3A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker ...
CVE-2026-1340CRITICAL9.8A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2026-1281CRITICAL9.8A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2026-22806CRITICAL9.1vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio...
CVE-2026-1453CRITICAL9.8A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated a...
CVE-2026-24054CRITICAL10Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-1595CRITICAL9.8A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /ad...
CVE-2026-1594CRITICAL9.8A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some...
CVE-2026-1593CRITICAL9.8A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-1590CRITICAL9.8A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now