2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12415CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th...
CVE-2026-31928CRITICAL9.8The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are ...
CVE-2026-53576CRITICAL10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for...
CVE-2026-49869CRITICAL10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr...
CVE-2026-54352CRITICAL9.6Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro...
CVE-2026-54351CRITICAL9.6Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce...
CVE-2026-54350CRITICAL9.8Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap...
CVE-2026-50137CRITICAL9.4Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp...
CVE-2026-53309CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() re...
CVE-2026-52785CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection ...
CVE-2026-52782CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through ...
CVE-2026-52780CRITICAL9.6OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning lea...
CVE-2026-46386CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke...
CVE-2026-33646CRITICAL9.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ...
CVE-2026-54636CRITICAL9.9Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system...
CVE-2026-45408CRITICAL9Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta...
CVE-2026-12411CRITICAL9.6Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r...
CVE-2026-0685CRITICAL9.8Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows...
CVE-2026-57658CRITICAL9.1Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
CVE-2026-56070CRITICAL9.3Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
CVE-2026-56068CRITICAL9.3Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
CVE-2026-56067CRITICAL9.3Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
CVE-2026-56062CRITICAL9.3Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
CVE-2026-56059CRITICAL9.9Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
CVE-2026-56058CRITICAL9.9Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now