2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-71801CRITICAL9.8An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token sec...
CVE-2026-36433CRITICAL9.8An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker exe...
CVE-2026-87911CRITICAL9.6An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres...
CVE-2026-54694CRITICAL9.6SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a s...
CVE-2026-87929CRITICAL9.8MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never c...
CVE-2026-47156CRITICAL9.3MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP...
CVE-2026-79689CRITICAL9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-68484CRITICAL9Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do...
CVE-2026-67403CRITICAL9Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level a...
CVE-2026-67401CRITICAL9.9A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr...
CVE-2026-22590CRITICAL9.1eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ...
CVE-2026-79941CRITICAL9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-86751CRITICAL9.6Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to r...
CVE-2026-85103CRITICAL9.8A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute a...
CVE-2026-85102CRITICAL9.8Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauth...
CVE-2026-80172CRITICAL9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-87827CRITICAL10Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfac...
CVE-2026-85978CRITICAL9.8An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A pat...
CVE-2026-56207CRITICAL9.8Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing...
CVE-2026-41871CRITICAL9.8Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability ...
CVE-2026-41869CRITICAL9.1Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST...
CVE-2026-79696CRITICAL10A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through ...
CVE-2026-16272CRITICAL9.1Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame...
CVE-2026-21096CRITICAL9.8Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attac...
CVE-2026-21095CRITICAL9.8Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attack...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now