2026 CVE Vulnerabilities

46,943 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-1589CRITICAL9.8A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil...
CVE-2026-1188CRITICAL9.8In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all suppor...
CVE-2026-1552CRITICAL9.8A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_In...
CVE-2026-24888CRITICAL9.8Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19....
CVE-2026-24857CRITICAL9.8`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar co...
CVE-2026-1547CRITICAL9.8A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi...
CVE-2026-1546CRITICAL9.8A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillI...
CVE-2026-1545CRITICAL9.8A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function...
CVE-2026-24769CRITICAL9NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)...
CVE-2026-1535CRITICAL9.8A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of t...
CVE-2026-1534CRITICAL9.8A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Adm...
CVE-2026-1533CRITICAL9.8A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ...
CVE-2026-24772CRITICAL9OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents...
CVE-2026-1056CRITICAL9.8The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida...
CVE-2026-24841CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection...
CVE-2026-24785CRITICAL9.1Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Vers...
CVE-2026-23830CRITICAL10SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `Async...
CVE-2026-24770CRITICAL9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, ...
CVE-2026-24740CRITICAL9.9Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell end...
CVE-2026-24858CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnaly...
CVE-2026-24881CRITICAL9.8In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause...
CVE-2026-22264CRITICAL9.1Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead ...
CVE-2026-22262CRITICAL9.8Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior ...
CVE-2026-22039CRITICAL9.9Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav...
CVE-2026-24874CRITICAL9.1Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now