2026 CVE Vulnerabilities

57,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15517HIGH7.3A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma...
CVE-2026-15516MEDIUM5.6A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/...
CVE-2026-15515HIGH7A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown process...
CVE-2026-15514HIGH7.3A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCS...
CVE-2026-15513MEDIUM6.3A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the f...
CVE-2026-15512MEDIUM6.3A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the ...
CVE-2026-15511CRITICAL9.8A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function sy...
CVE-2026-15510MEDIUM6.3A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. T...
CVE-2026-15509MEDIUM6.3A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON...
CVE-2026-15508MEDIUM6.3A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file...
CVE-2026-15507MEDIUM6.3A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file ...
CVE-2026-15506HIGH7.8A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func...
CVE-2026-15505LOW3.5A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra...
CVE-2026-10668MEDIUM4.6The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage ...
CVE-2026-10667HIGH7.8Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l...
CVE-2026-10666CRITICAL9.8parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the...
CVE-2026-10665HIGH7.4In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou...
CVE-2026-10664MEDIUM5The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src...
CVE-2026-10663MEDIUM6.1In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c...
CVE-2026-58596HIGH8.3Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o...
CVE-2026-15502MEDIUM6.3A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php o...
CVE-2026-15501MEDIUM6.3A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function T...
CVE-2026-61876CRITICAL9.4LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ...
CVE-2026-61875HIGH8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav...
CVE-2026-61874LOW3.1filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now