2026 CVE Vulnerabilities

64,732 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-79916CRITICAL9.1MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject con...
CVE-2026-77521CRITICAL10MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil...
CVE-2026-67827CRITICAL9.8Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote C...
CVE-2026-46649CRITICAL9.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-58491CRITICAL9.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/provider...
CVE-2026-93012CRITICAL9.8Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a...
CVE-2026-79920CRITICAL9.9Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/t...
CVE-2026-61674CRITICAL9.2Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0...
CVE-2026-85751CRITICAL9.8Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-ch...
CVE-2026-36469CRITICAL9.1CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Medi...
CVE-2026-94301CRITICAL9.8The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.ref...
CVE-2026-86473CRITICAL9.1Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client ...
CVE-2026-82187CRITICAL9.8The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded file...
CVE-2026-94101CRITICAL9.9A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function v...
CVE-2026-94100CRITICAL9.9A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of th...
CVE-2026-94099CRITICAL9.9A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of...
CVE-2026-94098CRITICAL9.1A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the fil...
CVE-2026-94097CRITICAL10A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-...
CVE-2026-94096CRITICAL9.9A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of...
CVE-2026-94095CRITICAL9.9A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown funct...
CVE-2026-94089CRITICAL10A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_aut...
CVE-2026-88857CRITICAL9.4Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension f...
CVE-2026-88856CRITICAL9.4Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension f...
CVE-2026-88854CRITICAL9.3Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 ...
CVE-2026-90817CRITICAL9.8An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import proce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now