2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-51536CRITICAL9.1In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length para...
CVE-2026-58409CRITICAL9.1ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve...
CVE-2026-6875CRITICAL9.5ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This v...
CVE-2026-61500CRITICAL9.8Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato...
CVE-2026-61462CRITICAL9.2mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re...
CVE-2026-57433CRITICAL9.8Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retr...
CVE-2026-13221CRITICAL9.1Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553...
CVE-2026-6847CRITICAL9.3Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu...
CVE-2026-61498CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php en...
CVE-2026-60121CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint...
CVE-2026-40469CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b...
CVE-2026-40468CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust...
CVE-2026-12257CRITICAL9.3Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located...
CVE-2026-14934CRITICAL9.4A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co...
CVE-2026-59518CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affe...
CVE-2026-59515CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-cop...
CVE-2026-57813CRITICAL9.8Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issu...
CVE-2026-57811CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-est...
CVE-2026-57770CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection...
CVE-2026-57744CRITICAL9.8Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injecti...
CVE-2026-57739CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newslet...
CVE-2026-57738CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affec...
CVE-2026-57726CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirk...
CVE-2026-57724CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki:...
CVE-2026-57719CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Mal...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now