2026 CVE Vulnerabilities

47,130 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22854CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive...
CVE-2026-22853CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not per...
CVE-2026-22852CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a h...
CVE-2026-22708CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi...
CVE-2026-22238CRITICAL9.8The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remot...
CVE-2026-22237CRITICAL9.8The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated rem...
CVE-2026-22236CRITICAL9.8The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated rem...
CVE-2026-23550CRITICAL9.8Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This...
CVE-2026-22686CRITICAL10Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sa...
CVE-2026-23478CRITICAL9.8Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JW...
CVE-2026-22871CRITICAL9.8GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exis...
CVE-2026-22869CRITICAL9.8Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allow...
CVE-2026-20963CRITICAL9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ...
CVE-2026-22755CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected de...
CVE-2026-0892CRITICAL9.8Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption a...
CVE-2026-0884CRITICAL9.8Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thund...
CVE-2026-0881CRITICAL10Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
CVE-2026-0879CRITICAL9.8Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1...
CVE-2026-0501CRITICAL9.9Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent...
CVE-2026-0491CRITICAL9.1SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module ...
CVE-2026-22214CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos ...
CVE-2026-22213CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapsli...
CVE-2026-22785CRITICAL9.8orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0...
CVE-2026-22781CRITICAL9.8TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable...
CVE-2026-22252CRITICAL9.9LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now