2026 CVE Vulnerabilities
44,969 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9455 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCer... |
| CVE-2026-9454 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGen... |
| CVE-2026-9436 | CRITICAL | 9.8 | 2.0% | May 25, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of ... |
| CVE-2026-9435 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of ... |
| CVE-2026-9434 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsC... |
| CVE-2026-9433 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRule... |
| CVE-2026-9432 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function set... |
| CVE-2026-2651 | CRITICAL | 9 | 0.3% | May 25, 2026 | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the... |
| CVE-2026-9408 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDh... |
| CVE-2026-9407 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is th... |
| CVE-2026-9406 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the fil... |
| CVE-2026-9405 | CRITICAL | 9.8 | 1.7% | May 25, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg o... |
| CVE-2026-9404 | CRITICAL | 9.8 | 1.7% | May 24, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file... |
| CVE-2026-9388 | CRITICAL | 9.8 | 2.1% | May 24, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setSchedule... |
| CVE-2026-9387 | CRITICAL | 9.8 | 1.7% | May 24, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpg... |
| CVE-2026-9386 | CRITICAL | 9.8 | 1.7% | May 24, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the f... |
| CVE-2026-9385 | CRITICAL | 9.8 | 1.7% | May 24, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg... |
| CVE-2026-9384 | CRITICAL | 9.8 | 1.7% | May 24, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisC... |
| CVE-2026-47280 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-42901 | CRITICAL | 10 | 0.3% | May 22, 2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-41090 | CRITICAL | 9.3 | 0.4% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-40412 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code ... |
| CVE-2026-33843 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized ... |
| CVE-2026-23652 | CRITICAL | 9.8 | 0.6% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u... |
| CVE-2026-48700 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now