2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-71640CRITICAL9.1An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe...
CVE-2026-45764CRITICAL9.1Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-19646CRITICAL9.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote...
CVE-2026-89094CRITICAL9.9Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files...
CVE-2026-85025CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and acc...
CVE-2026-75940CRITICAL9.1A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that c...
CVE-2026-89086CRITICAL9.1In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decodi...
CVE-2026-88062CRITICAL9.5OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, ...
CVE-2026-89049CRITICAL9.9A server-side request forgery issue due to improper validation of equivalent address representations in the port forward...
CVE-2026-89042CRITICAL9.1passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowin...
CVE-2026-68006CRITICAL9.1An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_...
CVE-2026-88044CRITICAL9.1rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70....
CVE-2026-85228CRITICAL9.1An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36...
CVE-2026-68488CRITICAL9.9A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privileg...
CVE-2026-68487CRITICAL9.9Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
CVE-2026-65639CRITICAL9.5OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who contro...
CVE-2026-65638CRITICAL9.2Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to exe...
CVE-2026-52098CRITICAL9.8An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoin...
CVE-2026-88899CRITICAL9.8knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode pro...
CVE-2026-88018CRITICAL9.8rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-81467CRITICAL9.8Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS C...
CVE-2026-81046CRITICAL9.4Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated...
CVE-2026-88008CRITICAL9.1Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards ...
CVE-2026-88007CRITICAL9.1Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypo...
CVE-2026-81800CRITICAL9.3Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now