2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-85043CRITICAL9.1Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access ...
CVE-2026-85042CRITICAL9.6Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code o...
CVE-2026-85394CRITICAL9.1python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded publi...
CVE-2026-85391CRITICAL9.8Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attac...
CVE-2026-82526CRITICAL9.8R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitr...
CVE-2026-58400CRITICAL9.1GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the S...
CVE-2026-84834CRITICAL9.8Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84814CRITICAL9.8Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84813CRITICAL9.3Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84768CRITICAL9.3Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-84753CRITICAL9.8Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-84238CRITICAL9.8Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
CVE-2026-85221CRITICAL9.1MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property w...
CVE-2026-85216CRITICAL9.8MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficien...
CVE-2026-85183CRITICAL9.3Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to es...
CVE-2026-85181CRITICAL9.8CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attac...
CVE-2026-85109CRITICAL9.8A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/f...
CVE-2026-82180CRITICAL9.5In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication polic...
CVE-2026-85165CRITICAL9.9n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed...
CVE-2026-85154CRITICAL9.8WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-r...
CVE-2026-85031CRITICAL9.9A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cste...
CVE-2026-80726CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when crea...
CVE-2026-78080CRITICAL9.3Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used i...
CVE-2026-78069CRITICAL9.5Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4...
CVE-2026-76178CRITICAL9.2A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now