2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-76244CRITICAL9.1stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse network...
CVE-2026-76243CRITICAL9.2stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments...
CVE-2026-76242CRITICAL9.1stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-...
CVE-2026-74804CRITICAL9.3Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filte...
CVE-2026-74803CRITICAL10Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbi...
CVE-2026-51366CRITICAL9.9SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary c...
CVE-2026-16019CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation ...
CVE-2026-73391CRITICAL9.3Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-73390CRITICAL9.8Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVE-2026-73389CRITICAL9.8Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVE-2026-73388CRITICAL9.3Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-73364CRITICAL9.8Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-73347CRITICAL9.8Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVE-2026-73185CRITICAL9.3Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-73183CRITICAL9.3Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-67364CRITICAL10Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9....
CVE-2026-66613CRITICAL9.8Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-19490CRITICAL9.8Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr...
CVE-2026-72889CRITICAL9.8Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves ...
CVE-2026-58082CRITICAL9.8The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ...
CVE-2026-58081CRITICAL9.8Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied outp...
CVE-2026-18937CRITICAL9The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o...
CVE-2026-18776CRITICAL9.8The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all...
CVE-2026-18051CRITICAL10The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil...
CVE-2026-18031CRITICAL9.8The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now