2026 CVE Vulnerabilities

46,944 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22709CRITICAL10vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototyp...
CVE-2026-22696CRITICAL9.3dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present ...
CVE-2026-1443CRITICAL9.8A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of th...
CVE-2026-24436CRITICAL9.8Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account l...
CVE-2026-24429CRITICAL9.8Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password f...
CVE-2026-1423CRITICAL9.8A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown fu...
CVE-2026-1422CRITICAL9.8A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown f...
CVE-2026-1420CRITICAL9.8A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This...
CVE-2026-1414CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impact...
CVE-2026-1413CRITICAL9.8A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the...
CVE-2026-1412CRITICAL9.8A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacte...
CVE-2026-22586CRITICAL9.8Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr...
CVE-2026-22585CRITICAL9.8Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, For...
CVE-2026-22583CRITICAL9.8Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing...
CVE-2026-22582CRITICAL9.8Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing...
CVE-2026-24423CRITICAL9.8SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in ...
CVE-2026-1364CRITICAL9.8IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to di...
CVE-2026-1363CRITICAL9.8IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticat...
CVE-2026-0794CRITICAL9.8ALGO 8180 IP Audio Alerter SIP Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote atta...
CVE-2026-0793CRITICAL9.8ALGO 8180 IP Audio Alerter InformaCast Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2026-0792CRITICAL9.8ALGO 8180 IP Audio Alerter SIP INVITE Alert-Info Stack-based Buffer Overflow Remote Code Execution Vulnerability. This v...
CVE-2026-0791CRITICAL9.8ALGO 8180 IP Audio Alerter SIP INVITE Replaces Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul...
CVE-2026-0787CRITICAL9.8ALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-0773CRITICAL9.8Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2026-0770CRITICAL9.8Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now