2026 CVE Vulnerabilities

43,950 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-8713CRITICAL9.1The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v...
CVE-2026-7515CRITICAL9.8The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi...
CVE-2026-54414CRITICAL9.8FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedF...
CVE-2026-40624CRITICAL9.8Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att...
CVE-2026-12046CRITICAL9.5Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit...
CVE-2026-47647CRITICAL9.9Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-49454CRITICAL9.1Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept ...
CVE-2026-49257CRITICAL10mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and...
CVE-2026-49252CRITICAL9.9deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers...
CVE-2026-43994CRITICAL9.8Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer ove...
CVE-2026-47846CRITICAL9.8Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrat...
CVE-2026-54390CRITICAL9.8JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticate...
CVE-2026-56020CRITICAL9.2The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie...
CVE-2026-55203CRITICAL9.1HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ...
CVE-2026-54103CRITICAL9.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-38717CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38716CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38715CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38714CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-9158CRITICAL9.8In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac...
CVE-2026-8024CRITICAL9.8A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor...
CVE-2026-54419CRITICAL9.8claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1...
CVE-2026-11718CRITICAL9.3An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-11717CRITICAL9.3An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-55742CRITICAL9.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now