2026 CVE Vulnerabilities

46,973 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22807CRITICAL9.8vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio...
CVE-2026-22793CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0...
CVE-2026-22792CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0...
CVE-2026-20045CRITICAL9.8A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag...
CVE-2026-24061CRITICAL9.8telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment ...
CVE-2026-0933CRITICAL9.9SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The is...
CVE-2026-21969CRITICAL9.8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Su...
CVE-2026-21962CRITICAL10Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo...
CVE-2026-21636CRITICAL10A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--...
CVE-2026-22844CRITICAL9.9A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting p...
CVE-2026-1221CRITICAL9.8PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowi...
CVE-2026-0907CRITICAL9.8Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo...
CVE-2026-0906CRITICAL9.8Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content...
CVE-2026-0905CRITICAL9.8Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a netw...
CVE-2026-23947CRITICAL9.8Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior ...
CVE-2026-23876CRITICAL9.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-22770CRITICAL9.8ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage me...
CVE-2026-1202CRITICAL9.8A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file cr...
CVE-2026-1179CRITICAL9.8A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the c...
CVE-2026-23944CRITICAL9.8Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthent...
CVE-2026-23885CRITICAL9.9Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3,...
CVE-2026-1178CRITICAL9.8A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of t...
CVE-2026-1177CRITICAL9.8A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the fil...
CVE-2026-23837CRITICAL9.8MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and ...
CVE-2026-1176CRITICAL9.8A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now