2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-77992CRITICAL9.5Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateCommen...
CVE-2026-76607CRITICAL10Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
CVE-2026-76606CRITICAL10Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
CVE-2026-76605CRITICAL10Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
CVE-2026-76604CRITICAL10Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP...
CVE-2026-76602CRITICAL9.3Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in l...
CVE-2026-76571CRITICAL9.3Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - T...
CVE-2026-75870CRITICAL9.1Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared...
CVE-2026-75866CRITICAL9.1Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant t...
CVE-2026-77946CRITICAL10A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe...
CVE-2026-78003CRITICAL9.8The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in...
CVE-2026-12710CRITICAL9.3A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025...
CVE-2026-77002CRITICAL9.8The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity ...
CVE-2026-77001CRITICAL9.8The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen...
CVE-2026-77000CRITICAL9.8The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with...
CVE-2026-49849CRITICAL9.1xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allo...
CVE-2026-77415CRITICAL9.3JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain s...
CVE-2026-77414CRITICAL9.3JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup fun...
CVE-2026-77413CRITICAL9.3JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lack...
CVE-2026-76904CRITICAL9.8GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v...
CVE-2026-62283CRITICAL9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 t...
CVE-2026-61539CRITICAL10Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference ...
CVE-2026-59989CRITICAL9.2Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine...
CVE-2026-77810CRITICAL9.9In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties i...
CVE-2026-62674CRITICAL9Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now