2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-79391CRITICAL9.8No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP por...
CVE-2026-71625CRITICAL9.8An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController...
CVE-2026-71624CRITICAL9.8An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class...
CVE-2026-81939CRITICAL9.1A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing func...
CVE-2026-78328CRITICAL9.1A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allow...
CVE-2026-78327CRITICAL9.1An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the Sonic...
CVE-2026-57163CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer o...
CVE-2026-57162CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer o...
CVE-2026-84961CRITICAL9.1undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and re...
CVE-2026-78745CRITICAL9.8An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via ...
CVE-2026-75430CRITICAL9.8PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without au...
CVE-2026-31020CRITICAL9.8In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content...
CVE-2026-18221CRITICAL9.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of cli...
CVE-2026-17207CRITICAL9.1IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to ...
CVE-2026-17057CRITICAL9.1IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to...
CVE-2026-77822CRITICAL9.6IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-s...
CVE-2026-75431CRITICAL9.1PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. Th...
CVE-2026-75429CRITICAL9.8PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/proces...
CVE-2026-75171CRITICAL9.8An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling c...
CVE-2026-75160CRITICAL9.1An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin...
CVE-2026-44402CRITICAL9.8Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmw...
CVE-2026-19274CRITICAL9.6IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authentic...
CVE-2026-18658CRITICAL9.8IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to S...
CVE-2026-85696CRITICAL9.8SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are ...
CVE-2026-85695CRITICAL9.4FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now