2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-58155CRITICAL9.3Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. ...
CVE-2026-58154CRITICAL9.2Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe...
CVE-2026-58150CRITICAL10Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This ...
CVE-2026-57834CRITICAL10Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser...
CVE-2026-41920CRITICAL9.3Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th...
CVE-2026-33267CRITICAL9.1Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 ...
CVE-2026-18191CRITICAL9.8VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to...
CVE-2026-63234CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63233CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63232CRITICAL9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro...
CVE-2026-63230CRITICAL9.1A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read ...
CVE-2026-63229CRITICAL9.1A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-...
CVE-2026-63227CRITICAL9.9An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR...
CVE-2026-13423CRITICAL9.8The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauth...
CVE-2026-18072CRITICAL9.8The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to ...
CVE-2026-64863CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server....
CVE-2026-62325CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver...
CVE-2026-54658CRITICAL9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u...
CVE-2026-6881CRITICAL9.4A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a...
CVE-2026-14976CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colle...
CVE-2026-14974CRITICAL9.8IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused...
CVE-2026-14973CRITICAL9.3IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's s...
CVE-2026-14512CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whi...
CVE-2026-14446CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminis...
CVE-2026-16184CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafte...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now