2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-60034CRITICAL9.4Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia i...
CVE-2026-60032CRITICAL9.4Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia ...
CVE-2026-12341CRITICAL9.8This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot...
CVE-2026-39878CRITICAL9.3Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration fo...
CVE-2026-54051CRITICAL9.9Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell comma...
CVE-2026-41521CRITICAL9.1xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s...
CVE-2026-41252CRITICAL9.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap...
CVE-2026-35048CRITICAL9.8The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d...
CVE-2026-51027CRITICAL9.9An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
CVE-2026-46428CRITICAL9.1lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug ...
CVE-2026-46412CRITICAL10@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support...
CVE-2026-35198CRITICAL9HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i...
CVE-2026-28220CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i...
CVE-2026-63071CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-62183CRITICAL9.8Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure...
CVE-2026-57308CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A...
CVE-2026-53421CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen...
CVE-2026-53405CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-12701CRITICAL9A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa...
CVE-2026-57309CRITICAL9.3A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec...
CVE-2026-64622CRITICAL9.3Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/...
CVE-2026-64621CRITICAL9.3FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl...
CVE-2026-64620CRITICAL9.1FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt...
CVE-2026-63756CRITICAL9.2SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows...
CVE-2026-16242CRITICAL9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now