2026 CVE Vulnerabilities

43,946 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-56345CRITICAL9.2AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end...
CVE-2026-5366CRITICAL9.9Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `...
CVE-2026-48939CRITICAL9.8A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature...
CVE-2026-48909CRITICAL9.5SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth...
CVE-2026-48908CRITICAL9.8A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulti...
CVE-2026-9265CRITICAL9.1Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_...
CVE-2026-11551CRITICAL9.8The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
CVE-2026-56081CRITICAL9.3Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound...
CVE-2026-56073CRITICAL9.4Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa...
CVE-2026-48582CRITICAL9.6Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-45480CRITICAL10Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48773CRITICAL9.8ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat...
CVE-2026-48772CRITICAL10ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ...
CVE-2026-51846CRITICAL9.8In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulne...
CVE-2026-51845CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the m...
CVE-2026-51844CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the c...
CVE-2026-51843CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w...
CVE-2026-9142CRITICAL9.3There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s...
CVE-2026-49871CRITICAL9.3Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows...
CVE-2026-49230CRITICAL9.1Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi...
CVE-2026-48137CRITICAL9.8There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a...
CVE-2026-44087CRITICAL9.1Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ...
CVE-2026-39999CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap...
CVE-2026-56141CRITICAL9.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ...
CVE-2026-50242CRITICAL9.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now