2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-50160CRITICAL10Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e...
CVE-2026-58521CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-58453CRITICAL9.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that...
CVE-2026-34117CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ...
CVE-2026-34116CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without...
CVE-2026-34115CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ...
CVE-2026-34114CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit...
CVE-2026-34113CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou...
CVE-2026-34112CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ...
CVE-2026-34111CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit...
CVE-2026-34110CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with...
CVE-2026-34109CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san...
CVE-2026-34108CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit...
CVE-2026-34107CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without ...
CVE-2026-34106CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without ...
CVE-2026-34105CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line ...
CVE-2026-34104CRITICAL9.8Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124)...
CVE-2026-34103CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): ...
CVE-2026-34102CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16...
CVE-2026-34101CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): ...
CVE-2026-34100CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE...
CVE-2026-34099CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S...
CVE-2026-58127CRITICAL9.8PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere...
CVE-2026-58126CRITICAL9.8PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to...
CVE-2026-58025CRITICAL9.8Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated wi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now