2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-88877CRITICAL9.8Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx pr...
CVE-2026-88869CRITICAL9.3AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in t...
CVE-2026-88864CRITICAL9.1Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase Postg...
CVE-2026-38626CRITICAL9.8Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.
CVE-2026-9163CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics Gi...
CVE-2026-78082CRITICAL9.3Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < ...
CVE-2026-8323CRITICAL9.3URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Con...
CVE-2026-88285CRITICAL9.4GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clie...
CVE-2026-88278CRITICAL9.8GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a ca...
CVE-2026-59679CRITICAL9fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using ...
CVE-2026-44950CRITICAL9fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. ...
CVE-2026-80352CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerabi...
CVE-2026-80351CRITICAL9.8Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. ...
CVE-2026-7188CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information...
CVE-2026-78361CRITICAL9.1The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation ch...
CVE-2026-77770CRITICAL10The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a valid...
CVE-2026-84939CRITICAL9.1Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary m...
CVE-2026-67593CRITICAL9.1A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis b...
CVE-2026-57967CRITICAL9.8An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and as...
CVE-2026-49364CRITICAL9.1An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during...
CVE-2026-19583CRITICAL9.9Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell...
CVE-2026-18351CRITICAL9.8The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all ver...
CVE-2026-87931CRITICAL9.6A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Im...
CVE-2026-88069CRITICAL9.3Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted ar...
CVE-2026-71805CRITICAL9.8An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now