2026 CVE Vulnerabilities

47,201 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-0501CRITICAL9.9Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent...
CVE-2026-0491CRITICAL9.1SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module ...
CVE-2026-22214CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos ...
CVE-2026-22213CRITICAL9.8RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapsli...
CVE-2026-22785CRITICAL9.8orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0...
CVE-2026-22781CRITICAL9.8TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable...
CVE-2026-22252CRITICAL9.9LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbi...
CVE-2026-0852CRITICAL9.8A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ...
CVE-2026-0851CRITICAL9.8A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of th...
CVE-2026-0821CRITICAL9.8A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_arra...
CVE-2026-22685CRITICAL9.8DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis...
CVE-2026-22687CRITICAL9.8WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-22600CRITICAL9.1OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in th...
CVE-2026-22584CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux al...
CVE-2026-20973CRITICAL9.1Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bou...
CVE-2026-0732CRITICAL9.8A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.as...
CVE-2026-22234CRITICAL9.8OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endp...
CVE-2026-22043CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed...
CVE-2026-22034CRITICAL9.8Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual...
CVE-2026-21891CRITICAL9.8ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and inc...
CVE-2026-0700CRITICAL9.8A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function...
CVE-2026-21881CRITICAL9.1Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a crit...
CVE-2026-21877CRITICAL9.9n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able...
CVE-2026-21875CRITICAL9.8ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind...
CVE-2026-21869CRITICAL9.8llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is par...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now