2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6556CRITICAL9.1@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argu...
CVE-2026-58016CRITICAL9.1A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection...
CVE-2026-8402CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni...
CVE-2026-53690CRITICAL9.3An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde...
CVE-2026-14162CRITICAL9.8Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated...
CVE-2026-13766CRITICAL9.8DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil...
CVE-2026-9711CRITICAL9.8The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the...
CVE-2026-12076CRITICAL9.3Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, ...
CVE-2026-12819CRITICAL9.3Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro...
CVE-2026-12818CRITICAL9.3Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-...
CVE-2026-12073CRITICAL9.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via a...
CVE-2026-55276CRITICAL9.1Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa...
CVE-2026-53434CRITICAL9.1Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect...
CVE-2026-57498CRITICAL9.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-39868CRITICAL9.1This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequ...
CVE-2026-37637CRITICAL9.1An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon...
CVE-2026-13763CRITICAL9.8Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote ...
CVE-2026-13762CRITICAL9.8Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to by...
CVE-2026-56782CRITICAL9.8Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that all...
CVE-2026-11720CRITICAL9.1A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr...
CVE-2026-13751CRITICAL9.6Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for...
CVE-2026-57331CRITICAL9.9Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVE-2026-56290CRITICAL9.8Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension...
CVE-2026-49048CRITICAL9.8The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenati...
CVE-2026-58053CRITICAL9.9Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now