2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-72529CRITICAL9.8A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4...
CVE-2026-71470CRITICAL9.1A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource ...
CVE-2026-49441CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 an...
CVE-2026-48162CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an...
CVE-2026-48024CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an...
CVE-2026-20359CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha...
CVE-2026-20358CRITICAL10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha...
CVE-2026-20357CRITICAL10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha...
CVE-2026-20318CRITICAL9.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t...
CVE-2026-20317CRITICAL10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t...
CVE-2026-20315CRITICAL10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t...
CVE-2026-20231CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t...
CVE-2026-20030CRITICAL10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha...
CVE-2026-62668CRITICAL9.4Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,...
CVE-2026-75954CRITICAL9.3Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and O...
CVE-2026-75949CRITICAL10Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - U...
CVE-2026-71960CRITICAL9.1Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosqui...
CVE-2026-53451CRITICAL9.8Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding....
CVE-2026-52889CRITICAL9.8Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults ...
CVE-2026-47187CRITICAL9.3SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can retu...
CVE-2026-45272CRITICAL9.4MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlie...
CVE-2026-16816CRITICAL9.9IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands ...
CVE-2026-16656CRITICAL9.8IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper auth...
CVE-2026-15068CRITICAL9.9IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary comma...
CVE-2026-15065CRITICAL9.1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now