2026 CVE Vulnerabilities

43,897 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-12417CRITICAL9.8The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi...
CVE-2026-12416CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a...
CVE-2026-12851CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12850CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12849CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12848CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12847CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12846CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12486CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12485CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-54588CRITICAL9.6Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacke...
CVE-2026-11807CRITICAL9.6A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible...
CVE-2026-53622CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/...
CVE-2026-48491CRITICAL10Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr...
CVE-2026-48020CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner...
CVE-2026-53753CRITICAL10Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in t...
CVE-2026-54316CRITICAL9.1Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved ...
CVE-2026-54257CRITICAL9.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 unti...
CVE-2026-54157CRITICAL9LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-53662CRITICAL9.6immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl...
CVE-2026-44726CRITICAL9.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib...
CVE-2026-55450CRITICAL9.3Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can...
CVE-2026-55447CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files th...
CVE-2026-54307CRITICAL9.6n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with edit...
CVE-2026-54305CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now