2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-45695CRITICAL9.8Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en...
CVE-2026-14890CRITICAL9.1SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d...
CVE-2026-56453CRITICAL9.8HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter...
CVE-2026-63306CRITICAL9.2stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e...
CVE-2026-63305CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ...
CVE-2026-63304CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list...
CVE-2026-11386CRITICAL9An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools)....
CVE-2026-22752CRITICAL9.6Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe...
CVE-2026-15925CRITICAL9.2Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed...
CVE-2026-12492CRITICAL9.8The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu...
CVE-2026-15013CRITICAL9.8The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algor...
CVE-2026-55652CRITICAL9.8Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest...
CVE-2026-55445CRITICAL9.3Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the...
CVE-2026-54458CRITICAL9.6WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi...
CVE-2026-52893CRITICAL9.2Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/user...
CVE-2026-52891CRITICAL9.9Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil...
CVE-2026-30623CRITICAL9.8LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application...
CVE-2026-30618CRITICAL9.8xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution...
CVE-2026-26718CRITICAL9.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att...
CVE-2026-54052CRITICAL9.9n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-52887CRITICAL10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-51380CRITICAL9.8Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S...
CVE-2026-49352CRITICAL9.89Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-...
CVE-2026-46339CRITICAL109Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/...
CVE-2026-46684CRITICAL9.5DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now