2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12717CRITICAL9.4An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Servi...
CVE-2026-80203CRITICAL9.8The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function ...
CVE-2026-77557CRITICAL9.8A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote...
CVE-2026-77554CRITICAL10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal...
CVE-2026-77553CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...
CVE-2026-77552CRITICAL9.8A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent...
CVE-2026-77551CRITICAL9A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulne...
CVE-2026-77550CRITICAL10A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo...
CVE-2026-77549CRITICAL9A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CR...
CVE-2026-77548CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-77547CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-77546CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-77532CRITICAL9.6A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-ena...
CVE-2026-18080CRITICAL9.8The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi...
CVE-2026-80349CRITICAL9.8TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's ...
CVE-2026-77545CRITICAL9A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug ...
CVE-2026-77543CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability...
CVE-2026-77542CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-77541CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability ...
CVE-2026-77540CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-77539CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-77537CRITICAL10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro...
CVE-2026-77536CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...
CVE-2026-77535CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-77534CRITICAL9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now