2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-60090CRITICAL9.8PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowled...
CVE-2026-56372CRITICAL9.1ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers...
CVE-2026-57827CRITICAL9.8Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFi...
CVE-2026-20744CRITICAL9.8The charging station websocket endpoint accepts connections without proper authentication, which could lead to privileg...
CVE-2026-15089CRITICAL9.1vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *....
CVE-2026-14480CRITICAL9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor...
CVE-2026-11913CRITICAL9.8vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
CVE-2026-55884CRITICAL9.2Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP...
CVE-2026-12535CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a...
CVE-2026-10768CRITICAL9.8Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov W...
CVE-2026-9726CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ...
CVE-2026-57807CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si...
CVE-2026-57216CRITICAL10RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str...
CVE-2026-57211CRITICAL10RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin stati...
CVE-2026-55879CRITICAL9.3OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom ...
CVE-2026-12761CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth...
CVE-2026-57158CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF...
CVE-2026-57156CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta...
CVE-2026-61459CRITICAL9.8MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect...
CVE-2026-5801CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics...
CVE-2026-59151CRITICAL9.6Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser...
CVE-2026-2397CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa...
CVE-2026-58492CRITICAL9.2grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t...
CVE-2026-51119CRITICAL9.1An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co...
CVE-2026-55500CRITICAL9.99Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now