2026 CVE Vulnerabilities

43,990 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-48797CRITICAL9.3Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th...
CVE-2026-48781CRITICAL9.9Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta...
CVE-2026-48745CRITICAL9.3Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca...
CVE-2026-48616CRITICAL9.3Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L...
CVE-2026-48055CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,...
CVE-2026-42380CRITICAL9.8Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
CVE-2026-40783CRITICAL9.9Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
CVE-2026-40749CRITICAL9.9Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
CVE-2026-40748CRITICAL9.9Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
CVE-2026-40747CRITICAL9.9Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
CVE-2026-40746CRITICAL9.9Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
CVE-2026-40725CRITICAL9.8Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
CVE-2026-39596CRITICAL9.3Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39589CRITICAL9.9Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
CVE-2026-39529CRITICAL9.8Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
CVE-2026-39438CRITICAL9.3Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
CVE-2026-32967CRITICAL9.1Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Ap...
CVE-2026-32966CRITICAL9.8DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler...
CVE-2026-27429CRITICAL9.8Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
CVE-2026-27395CRITICAL9.8Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
CVE-2026-27041CRITICAL9.9Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
CVE-2026-25470CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin fo...
CVE-2026-25446CRITICAL9.9Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
CVE-2026-24611CRITICAL9.1Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
CVE-2026-22340CRITICAL9.3Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now