2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-31309CRITICAL9.8Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a...
CVE-2026-54527CRITICAL9JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() metho...
CVE-2026-8801CRITICAL9.8Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: ...
CVE-2026-8649CRITICAL9.8Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report...
CVE-2026-29009CRITICAL9.8U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI...
CVE-2026-9074CRITICAL9.8IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner...
CVE-2026-59702CRITICAL9.3repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated ...
CVE-2026-3144CRITICAL9.8IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac...
CVE-2026-15062CRITICAL9.6SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo...
CVE-2026-58480CRITICAL9.8Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability...
CVE-2026-54061CRITICAL9.1Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e...
CVE-2026-8307CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig...
CVE-2026-14454CRITICAL9.8Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ...
CVE-2026-41042CRITICAL9.1Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java...
CVE-2026-9695CRITICAL9.8An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a...
CVE-2026-12153CRITICAL9.8The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1....
CVE-2026-9701CRITICAL9.8The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ...
CVE-2026-14487CRITICAL9.1The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2026-60002CRITICAL9.4ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This ...
CVE-2026-56843CRITICAL9.9Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo...
CVE-2026-59705CRITICAL9.8mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t...
CVE-2026-37271CRITICAL9.8Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA...
CVE-2026-37270CRITICAL9.8Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor...
CVE-2026-14740CRITICAL9.1DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr...
CVE-2026-14739CRITICAL9.8DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now