2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-73263CRITICAL9.9Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_conte...
CVE-2026-50561CRITICAL9.4Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version ...
CVE-2026-67285CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u...
CVE-2026-26035CRITICAL9.8An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6....
CVE-2026-67282CRITICAL10Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker ...
CVE-2026-66659CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome ...
CVE-2026-72526CRITICAL9.9A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man...
CVE-2026-70398CRITICAL9.6A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil...
CVE-2026-68067CRITICAL9.8The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active...
CVE-2026-67568CRITICAL9.3The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int...
CVE-2026-5917CRITICAL9.6libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command inj...
CVE-2026-66147CRITICAL9.4An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier...
CVE-2026-48765CRITICAL9.9TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa...
CVE-2026-73034CRITICAL9.8DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f...
CVE-2026-73032CRITICAL9.6PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav...
CVE-2026-66145CRITICAL9.1An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version...
CVE-2026-45618CRITICAL10LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit...
CVE-2026-16230CRITICAL9.8The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali...
CVE-2026-18691CRITICAL9An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc...
CVE-2026-73211CRITICAL9.8PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat...
CVE-2026-73090CRITICAL9.3PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi...
CVE-2026-71398CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-71362CRITICAL9.1Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att...
CVE-2026-69102CRITICAL9.8MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper...
CVE-2026-48381CRITICAL9Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now