2026 CVE Vulnerabilities

46,946 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-0773CRITICAL9.8Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2026-0770CRITICAL9.8Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This...
CVE-2026-0769CRITICAL9.8Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2026-0768CRITICAL9.8Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ...
CVE-2026-0764CRITICAL9.8GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2026-0763CRITICAL9.8GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This ...
CVE-2026-0761CRITICAL9.8Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerabi...
CVE-2026-0760CRITICAL9.8Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. Thi...
CVE-2026-0759CRITICAL9.8Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulner...
CVE-2026-0756CRITICAL9.8github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2026-0755CRITICAL9.8gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attack...
CVE-2026-24304CRITICAL9.9Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-24132CRITICAL9.8Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19....
CVE-2026-24306CRITICAL9.8Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-24305CRITICAL9.8Azure Entra ID Elevation of Privilege Vulnerability
CVE-2026-24124CRITICAL9.8Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,...
CVE-2026-21227CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-24058CRITICAL9.8Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication ...
CVE-2026-20912CRITICAL9.1Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a ...
CVE-2026-20897CRITICAL9.1Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos...
CVE-2026-20750CRITICAL9.1Gitea does not properly validate project ownership in organization project operations. A user with project write access ...
CVE-2026-1201CRITICAL9.4An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior...
CVE-2026-22278CRITICAL9.8Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v...
CVE-2026-24009CRITICAL9.8Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing ...
CVE-2026-23760CRITICAL9.8SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password res...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now