2026 CVE Vulnerabilities

47,106 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-1107CRITICAL9.8A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.p...
CVE-2026-1105CRITICAL9.8A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.cla...
CVE-2026-1062CRITICAL9.8A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lh...
CVE-2026-1061CRITICAL9.8A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file s...
CVE-2026-1059CRITICAL9.8A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by th...
CVE-2026-23800CRITICAL10Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe...
CVE-2026-23744CRITICAL9.8MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to r...
CVE-2026-0975CRITICAL9.8Delta Electronics DIAView has Command Injection vulnerability.
CVE-2026-22864CRITICAL9.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows b...
CVE-2026-23746CRITICAL9.3Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to...
CVE-2026-23527CRITICAL9.8H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP R...
CVE-2026-23519CRITICAL9.8RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-...
CVE-2026-22249CRITICAL9.8Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulner...
CVE-2026-22910CRITICAL9.1The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris...
CVE-2026-22909CRITICAL9.1Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete inst...
CVE-2026-22908CRITICAL9.1Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially comprom...
CVE-2026-22907CRITICAL9.1An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system dat...
CVE-2026-22859CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bou...
CVE-2026-22858CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in...
CVE-2026-22857CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_th...
CVE-2026-22855CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in th...
CVE-2026-22854CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive...
CVE-2026-22853CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not per...
CVE-2026-22852CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a h...
CVE-2026-22708CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now