2026 CVE Vulnerabilities

43,894 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-54825CRITICAL9.3Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
CVE-2026-54820CRITICAL9.3Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
CVE-2026-57926CRITICAL9.8In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-53914CRITICAL9.8In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
CVE-2026-57881CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-57880CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57879CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57878CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1....
CVE-2026-2053CRITICAL10The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ...
CVE-2026-48930CRITICAL9.8A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c...
CVE-2026-9222CRITICAL9.2Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe...
CVE-2026-40702CRITICAL9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res...
CVE-2026-56445CRITICAL9.1The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa...
CVE-2026-7531CRITICAL9.8Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1...
CVE-2026-57700CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i...
CVE-2026-56786CRITICAL9.8RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt...
CVE-2026-54917CRITICAL10SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the ...
CVE-2026-54089CRITICAL9.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-54088CRITICAL9.3File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-50549CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by...
CVE-2026-50548CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by...
CVE-2026-6094CRITICAL9.1Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ...
CVE-2026-56123CRITICAL9.8socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5...
CVE-2026-55413CRITICAL9.4ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-54030CRITICAL9.3LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now