2026 CVE Vulnerabilities

43,053 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-14205CRITICAL9.8The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid...
CVE-2026-14365CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...
CVE-2026-14364CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp...
CVE-2026-70332CRITICAL9.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-68823CRITICAL9.1Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n...
CVE-2026-65667CRITICAL10Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63508CRITICAL10Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev...
CVE-2026-62896CRITICAL9.6Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-62873CRITICAL9.8Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat...
CVE-2026-62836CRITICAL10Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized...
CVE-2026-62830CRITICAL9.9Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-59118CRITICAL9.3Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-59115CRITICAL9.9'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove...
CVE-2026-56162CRITICAL10Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56161CRITICAL9.6Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-50515CRITICAL9.9Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-50481CRITICAL9.9Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile...
CVE-2026-70558CRITICAL9.8Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) ...
CVE-2026-67689CRITICAL9.8SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or...
CVE-2026-67688CRITICAL9.8ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module....
CVE-2026-67622CRITICAL9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th...
CVE-2026-5857CRITICAL9.2Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ...
CVE-2026-53984CRITICAL9.1Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit...
CVE-2026-53983CRITICAL9.2Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital...
CVE-2026-48088CRITICAL9.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now