2026 CVE Vulnerabilities

43,970 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-11718CRITICAL9.3An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-11717CRITICAL9.3An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-55742CRITICAL9.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ...
CVE-2026-55740CRITICAL9.8Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe...
CVE-2026-12569CRITICAL9.8A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul...
CVE-2026-48768CRITICAL9.3TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is...
CVE-2026-54388CRITICAL9.3Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers w...
CVE-2026-54387CRITICAL9.3Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: ...
CVE-2026-48814CRITICAL9.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un...
CVE-2026-55196CRITICAL9.1Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo...
CVE-2026-53805CRITICAL9.8NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf...
CVE-2026-3894CRITICAL9.1Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects...
CVE-2026-30803CRITICAL9.1Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This ...
CVE-2026-20266CRITICAL9.1In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands ...
CVE-2026-53874CRITICAL9.8picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbit...
CVE-2026-53873CRITICAL9.8picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level pro...
CVE-2026-3490CRITICAL10picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolv...
CVE-2026-36418CRITICAL9.1JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi...
CVE-2026-20181CRITICAL9.1A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on ...
CVE-2026-55743CRITICAL9.6The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec...
CVE-2026-54812CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot...
CVE-2026-47103CRITICAL9.8Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ...
CVE-2026-42530CRITICAL9.2NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ...
CVE-2026-42055CRITICAL9.2NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ...
CVE-2026-54819CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now