2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-57517CRITICAL9.8Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote atta...
CVE-2026-24270CRITICAL9.8NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of...
CVE-2026-23537CRITICAL9.1A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat...
CVE-2026-57692CRITICAL9.8Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr...
CVE-2026-53355CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB...
CVE-2026-13603CRITICAL9The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially othe...
CVE-2026-14198CRITICAL9.1@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m...
CVE-2026-11387CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-10539CRITICAL9.5A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con...
CVE-2026-7840CRITICAL9.8UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func...
CVE-2026-7839CRITICAL9.1UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea...
CVE-2026-6070CRITICAL9.1The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to...
CVE-2026-56700CRITICAL9.8Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch...
CVE-2026-56415CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable...
CVE-2026-56413CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ...
CVE-2026-56278CRITICAL9.3Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp...
CVE-2026-55721CRITICAL9.3Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu...
CVE-2026-50110CRITICAL9.3Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu...
CVE-2026-14152CRITICAL9.6Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromi...
CVE-2026-14121CRITICAL9.8Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbit...
CVE-2026-14120CRITICAL9.6Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compr...
CVE-2026-14113CRITICAL9.6Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromis...
CVE-2026-14109CRITICAL9.6Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compro...
CVE-2026-14106CRITICAL9.6Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a...
CVE-2026-14104CRITICAL9.8Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now