2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-85688CRITICAL9.8TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-c...
CVE-2026-85684CRITICAL9.1marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitiz...
CVE-2026-85672CRITICAL9.8zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file exte...
CVE-2026-85667CRITICAL9.1xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthent...
CVE-2026-85663CRITICAL9.8Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr withou...
CVE-2026-85661CRITICAL9.8excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attacker...
CVE-2026-85597CRITICAL9.1Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows un...
CVE-2026-85596CRITICAL9.8Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The...
CVE-2026-85595CRITICAL9.8Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in t...
CVE-2026-85594CRITICAL9.8Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/s...
CVE-2026-85184CRITICAL9.1@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the ...
CVE-2026-82923CRITICAL9.8The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its RE...
CVE-2026-85085CRITICAL9.6The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who...
CVE-2026-80181CRITICAL9.1Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: thr...
CVE-2026-70403CRITICAL9.3XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log i...
CVE-2026-69657CRITICAL9.3XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in ...
CVE-2026-62928CRITICAL9.3XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
CVE-2026-15354CRITICAL9.8The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0....
CVE-2026-85509CRITICAL9.8FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC retu...
CVE-2026-85508CRITICAL9.8ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-o...
CVE-2026-85507CRITICAL9.8ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ip...
CVE-2026-85506CRITICAL9.8ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipm...
CVE-2026-85504CRITICAL9.8FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi...
CVE-2026-11613CRITICAL9.8The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5....
CVE-2026-85148CRITICAL9.8SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now