2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-71945CRITICAL9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj...
CVE-2026-71944CRITICAL9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj...
CVE-2026-14526CRITICAL9.8The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-46409CRITICAL9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v...
CVE-2026-48170CRITICAL9.1`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM ...
CVE-2026-47243CRITICAL9.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-50540CRITICAL9.6Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-61808CRITICAL9.8LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t...
CVE-2026-48039CRITICAL9.1Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A...
CVE-2026-71851CRITICAL9crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt...
CVE-2026-64637CRITICAL9.9Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an ...
CVE-2026-19264CRITICAL9.8Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat...
CVE-2026-66914CRITICAL9.2Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated...
CVE-2026-56793CRITICAL9.8Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An ...
CVE-2026-71560CRITICAL9.1Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0...
CVE-2026-71558CRITICAL9.8Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from ...
CVE-2026-54213CRITICAL9.2Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe...
CVE-2026-54212CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow...
CVE-2026-54211CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o...
CVE-2026-54210CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable...
CVE-2026-54203CRITICAL9.2Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti...
CVE-2026-16258CRITICAL9.8The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u...
CVE-2026-16038CRITICAL9.1The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or...
CVE-2026-14205CRITICAL9.8The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid...
CVE-2026-14365CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now