2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-45534CRITICAL9DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connecti...
CVE-2026-46421CRITICAL9.3The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d...
CVE-2026-62948CRITICAL9.6OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt...
CVE-2026-53513CRITICAL9.6Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'...
CVE-2026-53512CRITICAL9.1Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and ...
CVE-2026-50562CRITICAL9.3FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar...
CVE-2026-14960CRITICAL9.8Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interf...
CVE-2026-62378CRITICAL9RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS C...
CVE-2026-52843CRITICAL9.3Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest u...
CVE-2026-52842CRITICAL9.3Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the en...
CVE-2026-20157CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20156CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-50148CRITICAL9.1Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2...
CVE-2026-44986CRITICAL9.9Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation...
CVE-2026-61740CRITICAL9.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA...
CVE-2026-61736CRITICAL9.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* ...
CVE-2026-42533CRITICAL9.2A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string express...
CVE-2026-43637CRITICAL9.1Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files ou...
CVE-2026-61451CRITICAL9.6The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url fi...
CVE-2026-56400CRITICAL9.6open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow...
CVE-2026-56398CRITICAL9Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the ...
CVE-2026-13385CRITICAL9.5An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows...
CVE-2026-5270CRITICAL9.8An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage...
CVE-2026-5269CRITICAL9.8In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used fo...
CVE-2026-51808CRITICAL9.8Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the open...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now