2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-76158CRITICAL9.3External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v...
CVE-2026-76156CRITICAL9.4OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenti...
CVE-2026-76155CRITICAL9.3Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain...
CVE-2026-77651CRITICAL9.8The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,...
CVE-2026-77650CRITICAL9.8The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the ...
CVE-2026-77649CRITICAL9.8The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate...
CVE-2026-77647CRITICAL9.8SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August...
CVE-2026-77645CRITICAL9.2A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili...
CVE-2026-77644CRITICAL9.3A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise ...
CVE-2026-77642CRITICAL9.3tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected s...
CVE-2026-72843CRITICAL9.8The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/...
CVE-2026-69851CRITICAL9.9Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a ...
CVE-2026-69836CRITICAL10Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-69555CRITICAL10Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69400CRITICAL9.6Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-68789CRITICAL9.9Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut...
CVE-2026-68782CRITICAL9.9Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut...
CVE-2026-66309CRITICAL9.1Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-65816CRITICAL10Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a ...
CVE-2026-65801CRITICAL10Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov...
CVE-2026-65770CRITICAL10Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache ...
CVE-2026-62834CRITICAL9.8Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil...
CVE-2026-55769CRITICAL9.4CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and ...
CVE-2026-19437CRITICAL9.8IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov...
CVE-2026-18835CRITICAL9.9IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now