2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-57138CRITICAL9.9PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mo...
CVE-2026-52824CRITICAL9.1Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pub...
CVE-2026-62379CRITICAL9.8Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice P...
CVE-2026-62263CRITICAL9.2Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize ap...
CVE-2026-48717CRITICAL9.1Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler req...
CVE-2026-46619CRITICAL9.3Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authen...
CVE-2026-45052CRITICAL9.3Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receive...
CVE-2026-45051CRITICAL9.2Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serial...
CVE-2026-90711CRITICAL9.1proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs E...
CVE-2026-91003CRITICAL9.1A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of th...
CVE-2026-91001CRITICAL9.9A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of...
CVE-2026-90847CRITICAL9.1A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_se...
CVE-2026-12944CRITICAL9.6IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) ...
CVE-2026-86881CRITICAL9.1A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and i...
CVE-2026-84625CRITICAL9.1A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, mac...
CVE-2026-84609CRITICAL9.8A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Gold...
CVE-2026-84561CRITICAL9.8A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS ...
CVE-2026-84520CRITICAL9.8A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local atta...
CVE-2026-67399CRITICAL9.3Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute...
CVE-2026-65414CRITICAL9.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26....
CVE-2026-65381CRITICAL10A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the pro...
CVE-2026-53713CRITICAL9.1Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway...
CVE-2026-43790CRITICAL9.1The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, ...
CVE-2026-55209CRITICAL9.8resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata i...
CVE-2026-54334CRITICAL9.8UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now