CVEs from 2026

14,774 normalized CVEs published or assigned in this year.

Total
14,774
critical
critical 1,334
high
high 4,998
medium
medium 4,821
low
low 502
% Critical
9.0%
% with KEV
0.4%
% with exploit
0.7%

Top vendors

Top products

  • chrome 723
  • firepower_threat_defense_software 310
  • gcp 299
  • firepower_threat_defense 298
  • openclaw 172
  • commerce 104
  • netweaver_application_server_abap 102
  • commerce_b2b 89
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-2369 critical 9.1 9.1 3mo ago A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially acc…
CVE-2026-21671 critical 9.1 9.1 3mo ago A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
CVE-2026-28395 critical 9.1 9.1 3mo ago OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
CVE-2026-2880 critical 9.1 9.1 3mo ago @fastify/middie has Improper Path Normalization when Using Path-Scoped Middleware
CVE-2026-2953 critical 9.1 9.1 3mo ago A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulatio…
CVE-2026-45750 critical 9.0 9.0 19h ago Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix …
CVE-2026-45746 critical 9.0 9.0 19h ago Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Brok…
CVE-2026-36748 critical 9.0 9.0 3d ago RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
CVE-2026-9319 critical 9.0 9.0 5d ago IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
CVE-2026-9311 critical 9.0 9.0 5d ago IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
CVE-2026-45630 critical 9.0 9.0 8d ago Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users …
CVE-2026-9891 critical 9.0 9.0 9d ago Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome E…
CVE-2026-9881 critical 9.0 9.0 9d ago Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a cra…
CVE-2026-46833 critical 9.0 9.0 9d ago Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with…
CVE-2026-4408 critical 9.0 9.0 9d ago Important: samba security update
CVE-2026-32999 critical 9.0 9.0 9d ago Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the aff…
CVE-2026-48150 critical 9.0 9.0 10d ago Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for the app id in the x-…
CVE-2026-45721 critical 9.0 9.0 11d ago Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-4480 critical 9.0 9.0 11d ago Important: samba security update
CVE-2026-2651 critical 9.0 9.0 12d ago A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce …
CVE-2026-22314 critical 9.0 9.0 17d ago Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This…
CVE-2026-45375 critical 9.0 9.0 23d ago SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
CVE-2026-42457 critical 9.0 9.0 23d ago vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulner…
CVE-2026-41901 critical 9.0 9.0 25d ago Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
CVE-2026-44221 critical 9.0 9.0 25d ago ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
CVE-2026-42556 critical 9.0 9.0 29d ago Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their ow…
CVE-2026-33844 critical 9.0 9.0 1mo ago Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVE-2026-7372 critical 9.0 9.0 1mo ago A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker ca…
CVE-2026-42523 critical 9.0 9.0 1mo ago Jenkins GitHub Plugin has an XSS vulnerability
CVE-2026-5652 critical 9.0 9.0 2mo ago An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permiss…
CVE-2026-26149 critical 9.0 9.0 2mo ago Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
CVE-2026-34989 critical 9.0 9.0 2mo ago CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
CVE-2026-27540 critical 9.0 9.0 3mo ago Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue a…
CVE-2026-32635 critical 9.0 9.0 3mo ago Angular vulnerable to XSS in i18n attribute bindings