2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-100741CRITICAL9.8Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3...
CVE-2026-100721CRITICAL9vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `...
CVE-2026-100740CRITICAL9.9A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel...
CVE-2026-82901CRITICAL9.8The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file...
CVE-2026-85984CRITICAL9.8The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2026-97163CRITICAL10Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97161CRITICAL9.2Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6....
CVE-2026-97160CRITICAL9.4Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0...
CVE-2026-94132CRITICAL9.5Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterpri...
CVE-2026-94130CRITICAL9.3Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injectio...
CVE-2026-100717CRITICAL9.9froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return ...
CVE-2026-100716CRITICAL9.9Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails...
CVE-2026-100715CRITICAL9.6Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task...
CVE-2026-100714CRITICAL9.1Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings h...
CVE-2026-100706CRITICAL9.9kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace...
CVE-2026-18143CRITICAL9.8The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a...
CVE-2026-100382CRITICAL10Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Fo...
CVE-2026-97064CRITICAL9.1X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the d...
CVE-2026-97063CRITICAL9.1X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobi...
CVE-2026-84458CRITICAL9.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on ...
CVE-2026-48482CRITICAL9.4GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form imp...
CVE-2026-92161CRITICAL9.8FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7...
CVE-2026-62262CRITICAL9.1Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is ...
CVE-2026-42322CRITICAL9.1Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_page...
CVE-2026-39353CRITICAL9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now