2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-77148CRITICAL9.9A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-con...
CVE-2026-19586CRITICAL9.8A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as a...
CVE-2026-73257CRITICAL9.1Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can sen...
CVE-2026-73256CRITICAL9.1Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an ...
CVE-2026-73253CRITICAL9.1Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca...
CVE-2026-73251CRITICAL9.3Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t...
CVE-2026-63385CRITICAL9.2Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in ...
CVE-2026-63382CRITICAL9.2Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsi...
CVE-2026-53424CRITICAL9.1Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject...
CVE-2026-2334CRITICAL9.4An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s...
CVE-2026-77022CRITICAL9.9A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the...
CVE-2026-71428CRITICAL9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc...
CVE-2026-55642CRITICAL9.8dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au...
CVE-2026-18265CRITICAL9.8OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker...
CVE-2026-63039CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi...
CVE-2026-63038CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi...
CVE-2026-63037CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi...
CVE-2026-16926CRITICAL9.1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper...
CVE-2026-15706CRITICAL9.8Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla...
CVE-2026-28164CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. ...
CVE-2026-18482CRITICAL9.8Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-...
CVE-2026-77071CRITICAL9.8n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row G...
CVE-2026-77070CRITICAL9.8n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and...
CVE-2026-74018CRITICAL9.9Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVE-2026-74016CRITICAL9.9Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now