2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-56705CRITICAL9.8Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a...
CVE-2026-78267CRITICAL9.8Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78265CRITICAL9.8Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78262CRITICAL9.8Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-77337CRITICAL9.1CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio...
CVE-2026-32563CRITICAL9.8Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32559CRITICAL9.9Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVE-2026-32555CRITICAL9.3Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVE-2026-32554CRITICAL9.3Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVE-2026-77635CRITICAL9.2CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas...
CVE-2026-52490CRITICAL9.8An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces...
CVE-2026-78555CRITICAL9.4RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug...
CVE-2026-39975CRITICAL9.4Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly...
CVE-2026-76835CRITICAL9.1OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b...
CVE-2026-71933CRITICAL9.1Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul...
CVE-2026-71921CRITICAL9.8Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter...
CVE-2026-71914CRITICAL9.8Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i...
CVE-2026-78329CRITICAL9.8Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1...
CVE-2026-77915CRITICAL9.8rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-71300CRITICAL9.8Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam...
CVE-2026-66906CRITICAL9.1Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: ...
CVE-2026-76071CRITICAL9.8Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated...
CVE-2026-76070CRITICAL9.8Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated...
CVE-2026-78387CRITICAL9.4RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en...
CVE-2026-19874CRITICAL9.1A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now