2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7240 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAc... |
| CVE-2026-7204 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg... |
| CVE-2026-7203 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterR... |
| CVE-2026-7202 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the... |
| CVE-2026-32644 | CRITICAL | 9.8 | 0.2% | Apr 28, 2026 | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. |
| CVE-2026-40976 | CRITICAL | 9.1 | 0.5% | Apr 28, 2026 | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoint... |
| CVE-2026-40974 | CRITICAL | 9.8 | 0.2% | Apr 28, 2026 | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to... |
| CVE-2026-40971 | CRITICAL | 9.1 | 0.2% | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w... |
| CVE-2026-7156 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /c... |
| CVE-2026-7155 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPa... |
| CVE-2026-7154 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of... |
| CVE-2026-7153 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMin... |
| CVE-2026-7152 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf... |
| CVE-2026-35903 | CRITICAL | 9.8 | 0.5% | Apr 27, 2026 | MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP s... |
| CVE-2026-31255 | CRITICAL | 9.8 | 1.1% | Apr 27, 2026 | A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/S... |
| CVE-2026-7140 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file ... |
| CVE-2026-7139 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the fi... |
| CVE-2026-7138 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg ... |
| CVE-2026-7137 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorage... |
| CVE-2026-7136 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg... |
| CVE-2026-41462 | CRITICAL | 9.8 | 0.6% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality ... |
| CVE-2026-30352 | CRITICAL | 9.8 | 0.6% | Apr 27, 2026 | A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allow... |
| CVE-2026-40514 | CRITICAL | 9.1 | 0.2% | Apr 27, 2026 | SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t... |
| CVE-2026-7125 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEa... |
| CVE-2026-7124 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now