2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-64874CRITICAL9.8Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i...
CVE-2026-64873CRITICAL9.8Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re...
CVE-2026-15015CRITICAL9.8The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-15011CRITICAL9.8The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame...
CVE-2026-14282CRITICAL9.8The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ...
CVE-2026-16723CRITICAL9A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ...
CVE-2026-60372CRITICAL9.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60369CRITICAL9.9Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60367CRITICAL9.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60366CRITICAL10Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-64798CRITICAL9.1Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also...
CVE-2026-64796CRITICAL9.8Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both t...
CVE-2026-64793CRITICAL9.1Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere ext...
CVE-2026-64829CRITICAL9.1Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta...
CVE-2026-13072CRITICAL9.2When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du...
CVE-2026-16624CRITICAL9.6Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on...
CVE-2026-16606CRITICAL9.8A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow...
CVE-2026-2395CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info...
CVE-2026-62144CRITICAL9.1An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an...
CVE-2026-50252CRITICAL9.3In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret...
CVE-2026-16232CRITICAL9.8An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at...
CVE-2026-8152CRITICAL9.3Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) atta...
CVE-2026-65590CRITICAL9.8n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/...
CVE-2026-63048CRITICAL9.4Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ...
CVE-2026-56820CRITICAL9.1Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now