2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-56057CRITICAL9.8Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
CVE-2026-56036CRITICAL9.3Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
CVE-2026-56034CRITICAL9.3Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
CVE-2026-56033CRITICAL9.8Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
CVE-2026-56032CRITICAL9.8Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
CVE-2026-56030CRITICAL9.8Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
CVE-2026-56028CRITICAL9.8Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 vers...
CVE-2026-56027CRITICAL9.9Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
CVE-2026-54831CRITICAL9.3Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
CVE-2026-54827CRITICAL9.3Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
CVE-2026-54825CRITICAL9.3Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
CVE-2026-54820CRITICAL9.3Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
CVE-2026-57926CRITICAL9.8In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-53914CRITICAL9.8In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
CVE-2026-57881CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-57880CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57879CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57878CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1....
CVE-2026-2053CRITICAL10The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ...
CVE-2026-48930CRITICAL9.8A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c...
CVE-2026-9222CRITICAL9.2Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe...
CVE-2026-40702CRITICAL9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res...
CVE-2026-56445CRITICAL9.1The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa...
CVE-2026-7531CRITICAL9.8Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1...
CVE-2026-57700CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now