2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-62392CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin...
CVE-2026-62390CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba...
CVE-2026-10577CRITICAL10A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb...
CVE-2026-62422CRITICAL9.8In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 aut...
CVE-2026-58319CRITICAL9.1Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated ...
CVE-2026-56451CRITICAL10A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate...
CVE-2026-3014CRITICAL9.1Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerabilit...
CVE-2026-15043CRITICAL9.8DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, ...
CVE-2026-59084CRITICAL9.1Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc...
CVE-2026-59083CRITICAL9.1Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra...
CVE-2026-57898CRITICAL9In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen...
CVE-2026-15183CRITICAL9.2Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can...
CVE-2026-11563CRITICAL9.6The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletio...
CVE-2026-44761CRITICAL9.1SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from samp...
CVE-2026-44747CRITICAL9.9SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management t...
CVE-2026-27690CRITICAL9.1Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially craf...
CVE-2026-58102CRITICAL9.1Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID...
CVE-2026-62327CRITICAL9.39Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac...
CVE-2026-59801CRITICAL9.89Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact...
CVE-2026-52533CRITICAL9.8An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component...
CVE-2026-51821CRITICAL9.8SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitra...
CVE-2026-51541CRITICAL9.1OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit re...
CVE-2026-51540CRITICAL9.8OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer...
CVE-2026-51538CRITICAL9.1EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of en...
CVE-2026-51537CRITICAL9.1EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now