2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-53459CRITICAL9.3Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and p...
CVE-2026-45579CRITICAL9.9DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1...
CVE-2026-12351CRITICAL9.8IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 L...
CVE-2026-11928CRITICAL9.8IBM Verify Identity Access is vulnerable to a buffer overflow attack.
CVE-2026-11921CRITICAL9.1IBM Verify Identity Access containers may not apply management password change operations correctly.
CVE-2026-89026CRITICAL9.8The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS...
CVE-2026-53710CRITICAL10MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa...
CVE-2026-46488CRITICAL9.1motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w...
CVE-2026-91949CRITICAL9.3FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated at...
CVE-2026-77972CRITICAL9Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS respo...
CVE-2026-77866CRITICAL9Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reac...
CVE-2026-55211CRITICAL9.8Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fiel...
CVE-2026-37152CRITICAL9.8TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.
CVE-2026-88617CRITICAL9.8SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to ...
CVE-2026-79303CRITICAL9.9kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without t...
CVE-2026-63696CRITICAL9.1Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerab...
CVE-2026-63695CRITICAL9.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticate...
CVE-2026-61549CRITICAL9Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_op...
CVE-2026-59971CRITICAL10MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2...
CVE-2026-55158CRITICAL9.1Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1,...
CVE-2026-46495CRITICAL9.2OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/...
CVE-2026-39919CRITICAL9.8Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjp...
CVE-2026-77179CRITICAL9.4On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file...
CVE-2026-92079CRITICAL9.1Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunde...
CVE-2026-92075CRITICAL9.1Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now