2026 CVE Vulnerabilities

61,244 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-38063CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via...
CVE-2026-38062CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat...
CVE-2026-38061CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum...
CVE-2026-38060CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p...
CVE-2026-37216MEDIUM6.1Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
CVE-2026-36933MEDIUM6.8An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi...
CVE-2026-36670HIGH8.8A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr...
CVE-2026-36537CRITICAL9.8ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The applica...
CVE-2026-36521MEDIUM6.1PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
CVE-2026-36213HIGH7.8An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e...
CVE-2026-30121CRITICAL9.1remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
CVE-2026-30120CRITICAL9.8remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2026-11931MEDIUM6.8Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok...
CVE-2026-8358MEDIUM5.4LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ...
CVE-2026-8357HIGH7.8LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very...
CVE-2026-8356MEDIUM5.4LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c...
CVE-2026-6047MEDIUM5.4LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars...
CVE-2026-6045MEDIUM5.4LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ...
CVE-2026-6040HIGH7.3A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f...
CVE-2026-6039MEDIUM5.4LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ...
CVE-2026-49294MEDIUM6.1Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and...
CVE-2026-47777HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ...
CVE-2026-20262MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-9863HIGH8.8Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta...
CVE-2026-9862CRITICAL9.8Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now