2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-52439CRITICAL9.8An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p...
CVE-2026-49035CRITICAL9.2The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execu...
CVE-2026-47724CRITICAL9.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/...
CVE-2026-15981CRITICAL9.8The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a...
CVE-2026-15967CRITICAL9.8Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2...
CVE-2026-15966CRITICAL9.8Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue af...
CVE-2026-15630CRITICAL9.9A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any...
CVE-2026-10697CRITICAL9.8Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,...
CVE-2026-63359CRITICAL9.8The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att...
CVE-2026-47670CRITICAL9.4DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio...
CVE-2026-47669CRITICAL9.3DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api...
CVE-2026-6516CRITICAL10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...
CVE-2026-47752CRITICAL9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S...
CVE-2026-47668CRITICAL10DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star...
CVE-2026-44210CRITICAL9.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-65761CRITICAL9.3Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat...
CVE-2026-65760CRITICAL9.2Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0...
CVE-2026-15617CRITICAL9.1Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut...
CVE-2026-15616CRITICAL9.1Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem...
CVE-2026-15612CRITICAL9.1Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication...
CVE-2026-15611CRITICAL9.1Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id...
CVE-2026-65689CRITICAL9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its datab...
CVE-2026-65688CRITICAL9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now