2026 CVE Vulnerabilities

47,166 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-22236CRITICAL9.8The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated rem...
CVE-2026-23550CRITICAL9.8Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This...
CVE-2026-22686CRITICAL10Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sa...
CVE-2026-23478CRITICAL9.8Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JW...
CVE-2026-22871CRITICAL9.8GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exis...
CVE-2026-22869CRITICAL9.8Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allow...
CVE-2026-20963CRITICAL9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ...
CVE-2026-22755CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected de...
CVE-2026-0892CRITICAL9.8Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption a...
CVE-2026-0884CRITICAL9.8Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thund...
CVE-2026-0881CRITICAL10Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
CVE-2026-0879CRITICAL9.8Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1...
CVE-2026-0501CRITICAL9.9Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent...
CVE-2026-0491CRITICAL9.1SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module ...
CVE-2026-22214CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos ...
CVE-2026-22213CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapsli...
CVE-2026-22785CRITICAL9.8orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0...
CVE-2026-22781CRITICAL9.8TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable...
CVE-2026-22252CRITICAL9.9LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbi...
CVE-2026-0852CRITICAL9.8A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ...
CVE-2026-0851CRITICAL9.8A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of th...
CVE-2026-0821CRITICAL9.8A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_arra...
CVE-2026-22685CRITICAL9.8DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis...
CVE-2026-22687CRITICAL9.8WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-22600CRITICAL9.1OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now