2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-81096CRITICAL10ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat...
CVE-2026-81094CRITICAL9.1The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked...
CVE-2026-78251CRITICAL9.3DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate...
CVE-2026-75871CRITICAL9.6GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1...
CVE-2026-75357CRITICAL9.8An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili...
CVE-2026-57499CRITICAL9.1Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log...
CVE-2026-26897CRITICAL9.8An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain ...
CVE-2026-16279CRITICAL9.3An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Releas...
CVE-2026-81675CRITICAL9.3The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter....
CVE-2026-81674CRITICAL9.3The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized in...
CVE-2026-81673CRITICAL9.3The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. Th...
CVE-2026-81672CRITICAL9.3SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video pa...
CVE-2026-74233CRITICAL9.8Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242...
CVE-2026-74232CRITICAL9.8Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ...
CVE-2026-78292CRITICAL9.8Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78288CRITICAL9.3Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
CVE-2026-78286CRITICAL9.8Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-78274CRITICAL9.1Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78260CRITICAL9.3Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
CVE-2026-32566CRITICAL9.8Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32479CRITICAL9.3Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
CVE-2026-77991CRITICAL9.4Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The admin...
CVE-2026-77016CRITICAL9.6The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate prof...
CVE-2026-59270CRITICAL9.1Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative creden...
CVE-2026-47892CRITICAL9.8A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now