2026 CVE Vulnerabilities

44,013 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27429CRITICAL9.8Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
CVE-2026-27395CRITICAL9.8Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
CVE-2026-27041CRITICAL9.9Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
CVE-2026-25470CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin fo...
CVE-2026-25446CRITICAL9.9Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
CVE-2026-24611CRITICAL9.1Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
CVE-2026-22340CRITICAL9.3Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.
CVE-2026-22332CRITICAL9.3Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.
CVE-2026-22327CRITICAL9.9Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
CVE-2026-12440CRITICAL9.6Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to po...
CVE-2026-10094CRITICAL9.8A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS De...
CVE-2026-0092CRITICAL10In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead...
CVE-2026-48776CRITICAL9.1LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs fro...
CVE-2026-46978CRITICAL10Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported...
CVE-2026-46964CRITICAL9.9Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level...
CVE-2026-46963CRITICAL9.9Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level...
CVE-2026-46949CRITICAL9.1Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operatio...
CVE-2026-46946CRITICAL9.1Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver...
CVE-2026-46945CRITICAL9.1Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver...
CVE-2026-46944CRITICAL9.1Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver...
CVE-2026-46933CRITICAL9.9Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). S...
CVE-2026-46930CRITICAL9.1Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (compon...
CVE-2026-46919CRITICAL9.8Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp...
CVE-2026-46918CRITICAL9.9Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Int...
CVE-2026-46913CRITICAL9.3Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Su...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now