2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7123 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-... |
| CVE-2026-7122 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file... |
| CVE-2026-7121 | CRITICAL | 9.8 | 1.9% | Apr 27, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-b... |
| CVE-2026-33453 | CRITICAL | 10 | 6.2% | Apr 27, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap ... |
| CVE-2026-22337 | CRITICAL | 9.8 | 0.3% | Apr 27, 2026 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This is... |
| CVE-2026-22336 | CRITICAL | 9.3 | 0.3% | Apr 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Bookin... |
| CVE-2026-41409 | CRITICAL | 9.8 | 0.5% | Apr 27, 2026 | The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classe... |
| CVE-2026-33454 | CRITICAL | 9.4 | 0.6% | Apr 27, 2026 | The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the ... |
| CVE-2026-41635 | CRITICAL | 9.8 | 0.6% | Apr 27, 2026 | Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types)... |
| CVE-2026-40860 | CRITICAL | 9.8 | 0.9% | Apr 27, 2026 | JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payloa... |
| CVE-2026-40453 | CRITICAL | 9.9 | 0.9% | Apr 27, 2026 | The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such a... |
| CVE-2026-42363 | CRITICAL | 9.3 | 0.2% | Apr 27, 2026 | An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Uti... |
| CVE-2026-7037 | CRITICAL | 9.8 | 1.8% | Apr 26, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassC... |
| CVE-2026-7036 | CRITICAL | 9.8 | 0.5% | Apr 26, 2026 | A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerf... |
| CVE-2026-6987 | CRITICAL | 9.8 | 3.1% | Apr 25, 2026 | A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart o... |
| CVE-2026-31685 | CRITICAL | 9.4 | 0.3% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header fo... |
| CVE-2026-31682 | CRITICAL | 9.1 | 0.4% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND... |
| CVE-2026-6951 | CRITICAL | 9.8 | 0.9% | Apr 25, 2026 | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix ... |
| CVE-2026-41478 | CRITICAL | 9.9 | 0.3% | Apr 24, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a... |
| CVE-2026-41473 | CRITICAL | 9.1 | 0.8% | Apr 24, 2026 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints... |
| CVE-2026-41248 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @c... |
| CVE-2026-41475 | CRITICAL | 9.1 | 0.5% | Apr 24, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea... |
| CVE-2026-41428 | CRITICAL | 9.1 | 0.4% | Apr 24, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expr... |
| CVE-2026-41492 | CRITICAL | 9.8 | 2.2% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through... |
| CVE-2026-41415 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now