2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-76174CRITICAL9.4Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The a...
CVE-2026-19117CRITICAL9.8Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and...
CVE-2026-66786CRITICAL9.1A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from th...
CVE-2026-53671CRITICAL9.3PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstra...
CVE-2026-53670CRITICAL9.3PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Pre...
CVE-2026-53649CRITICAL9.6Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1...
CVE-2026-20279CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t...
CVE-2026-20274CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t...
CVE-2026-20212CRITICAL9.8A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remo...
CVE-2026-53611CRITICAL9.8Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet...
CVE-2026-82955CRITICAL9In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance in...
CVE-2026-77009CRITICAL9.9The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user...
CVE-2026-4357CRITICAL10The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as wel...
CVE-2026-73475CRITICAL9.1Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce Pa...
CVE-2026-84803CRITICAL9SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extensio...
CVE-2026-84795CRITICAL9.8Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactiva...
CVE-2026-81294CRITICAL9.8Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVE-2026-81286CRITICAL9.3Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
CVE-2026-78657CRITICAL9.8The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien...
CVE-2026-9055CRITICAL9.8The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-84699CRITICAL9.1Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset...
CVE-2026-84354CRITICAL9.6Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging socia...
CVE-2026-84353CRITICAL9.6Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leve...
CVE-2026-84352CRITICAL9.6Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbit...
CVE-2026-84333CRITICAL9.6Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now