2026 CVE Vulnerabilities

43,090 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-67689CRITICAL9.8SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or...
CVE-2026-67688CRITICAL9.8ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module....
CVE-2026-67622CRITICAL9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th...
CVE-2026-5857CRITICAL9.2Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ...
CVE-2026-53984CRITICAL9.1Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit...
CVE-2026-53983CRITICAL9.2Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital...
CVE-2026-48088CRITICAL9.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48087CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48086CRITICAL9.9OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48085CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-43632CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to...
CVE-2026-43631CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se...
CVE-2026-43629CRITICAL9.2llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe...
CVE-2026-3418CRITICAL9.1The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti...
CVE-2026-19175CRITICAL9.6Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s...
CVE-2026-19171CRITICAL9.6Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per...
CVE-2026-19170CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per...
CVE-2026-19166CRITICAL9.6Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p...
CVE-2026-19164CRITICAL9.6Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker ...
CVE-2026-19157CRITICAL9.6Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall...
CVE-2026-19149CRITICAL9.6Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor...
CVE-2026-18367CRITICAL9.3A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS ...
CVE-2026-17032CRITICAL9.8Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo...
CVE-2026-15734CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att...
CVE-2026-15733CRITICAL9.8A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now