2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-72599CRITICAL9.8An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne...
CVE-2026-72550CRITICAL9.8An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex...
CVE-2026-13738CRITICAL9.2CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft...
CVE-2026-13737CRITICAL9.2CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg...
CVE-2026-58231CRITICAL10SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf...
CVE-2026-10579CRITICAL9.8A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v...
CVE-2026-19516CRITICAL9.1A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf...
CVE-2026-13716CRITICAL9.1Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u...
CVE-2026-19425CRITICAL9.8Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re...
CVE-2026-44758CRITICAL9.1SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted...
CVE-2026-34265CRITICAL9.8SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars...
CVE-2026-48161CRITICAL9.3react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain...
CVE-2026-72911CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat...
CVE-2026-72904CRITICAL9.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ...
CVE-2026-48160CRITICAL9.3react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau...
CVE-2026-18948CRITICAL9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic...
CVE-2026-14450CRITICAL9.9A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy...
CVE-2026-72902CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to...
CVE-2026-72901CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-pri...
CVE-2026-72886CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u...
CVE-2026-72882CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can crea...
CVE-2026-72880CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in pack...
CVE-2026-72879CRITICAL9.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa...
CVE-2026-72878CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c...
CVE-2026-72877CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now