2026 CVE Vulnerabilities

46,973 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-24132CRITICAL9.8Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19....
CVE-2026-24306CRITICAL9.8Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-24305CRITICAL9.8Azure Entra ID Elevation of Privilege Vulnerability
CVE-2026-24124CRITICAL9.8Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,...
CVE-2026-21227CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-24058CRITICAL9.8Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication ...
CVE-2026-20912CRITICAL9.1Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a ...
CVE-2026-20897CRITICAL9.1Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos...
CVE-2026-20750CRITICAL9.1Gitea does not properly validate project ownership in organization project operations. A user with project write access ...
CVE-2026-1201CRITICAL9.4An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior...
CVE-2026-22278CRITICAL9.8Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v...
CVE-2026-24009CRITICAL9.8Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing ...
CVE-2026-23760CRITICAL9.8SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password res...
CVE-2026-1325CRITICAL9.8A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This a...
CVE-2026-1324CRITICAL9.8A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this iss...
CVE-2026-1331CRITICAL9.8MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote ...
CVE-2026-0920CRITICAL9.8The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio...
CVE-2026-24042CRITICAL9.8Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly acces...
CVE-2026-24002CRITICAL9.6Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formu...
CVE-2026-23966CRITICAL9.1sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key r...
CVE-2026-23958CRITICAL9.8Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the...
CVE-2026-23873CRITICAL9hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vuln...
CVE-2026-23736CRITICAL9.8seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio...
CVE-2026-23524CRITICAL9.8Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and belo...
CVE-2026-23518CRITICAL9.8Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now