2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-59706CRITICAL9.3mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f...
CVE-2026-46354CRITICAL9.1Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29...
CVE-2026-59707CRITICAL9.2LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al...
CVE-2026-58473CRITICAL9.3Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite...
CVE-2026-59800CRITICAL9.89Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i...
CVE-2026-13020CRITICAL9.8A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on ...
CVE-2026-13019CRITICAL9.8Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit...
CVE-2026-53483CRITICAL9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-53481CRITICAL9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-33264CRITICAL9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe...
CVE-2026-4375CRITICAL9The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to...
CVE-2026-14345CRITICAL9.8The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re...
CVE-2026-12375CRITICAL9.8The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny...
CVE-2026-34048CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34047CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34037CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-57572CRITICAL10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-...
CVE-2026-57571CRITICAL9.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil...
CVE-2026-54763CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA...
CVE-2026-42341CRITICAL9.2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti...
CVE-2026-34038CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-11405CRITICAL9.8The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8...
CVE-2026-9182CRITICAL9.8Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is...
CVE-2026-48614CRITICAL9.9An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat...
CVE-2026-48316CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now