2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-16349CRITICAL9.8Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-65008CRITICAL9.8Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/...
CVE-2026-65007CRITICAL9.6The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the pl...
CVE-2026-1617CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica...
CVE-2026-64606CRITICAL9.8Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb...
CVE-2026-64609CRITICAL9.1Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVa...
CVE-2026-64608CRITICAL9.8Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa...
CVE-2026-62415CRITICAL9.1Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe...
CVE-2026-13439CRITICAL9.8The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin...
CVE-2026-15901CRITICAL9.6Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap...
CVE-2026-15900CRITICAL9.6Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perfo...
CVE-2026-15899CRITICAL9.6Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially...
CVE-2026-64625CRITICAL9.8AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-q...
CVE-2026-52656CRITICAL9.8An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a...
CVE-2026-53595CRITICAL9.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public ...
CVE-2026-13380CRITICAL9VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent...
CVE-2026-63767CRITICAL9.8ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t...
CVE-2026-63766CRITICAL9.8GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, a...
CVE-2026-44231CRITICAL9.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prio...
CVE-2026-16337CRITICAL9.4Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-...
CVE-2026-64193CRITICAL9.8Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EX...
CVE-2026-62414CRITICAL9.1Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ...
CVE-2026-61900CRITICAL10Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla exten...
CVE-2026-61425CRITICAL9.4Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a...
CVE-2026-61424CRITICAL10Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla ext...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now