2026 CVE Vulnerabilities

61,653 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40215HIGH7.4A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau...
CVE-2026-11585MEDIUM6.3A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of...
CVE-2026-49141HIGH7.1WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent...
CVE-2026-47345MEDIUM5.1Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting...
CVE-2026-47344LOW2.1When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa...
CVE-2026-46484HIGH8.1Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable...
CVE-2026-40519HIGH7.7Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut...
CVE-2026-35058MEDIUM6.5Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t...
CVE-2026-11584MEDIUM6.3A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the...
CVE-2026-11583MEDIUM6.3A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function o...
CVE-2026-11582HIGH7.3A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function...
CVE-2026-52778CRITICAL9.8YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar f...
CVE-2026-46490HIGH8.8samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca...
CVE-2026-46486MEDIUM5.3MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potentia...
CVE-2026-11559MEDIUM6.3A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account...
CVE-2026-11558MEDIUM6.3A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function ...
CVE-2026-11557HIGH8.8A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the f...
CVE-2026-11393CRITICAL9Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might a...
CVE-2026-10787MEDIUM4.3Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user t...
CVE-2026-10786MEDIUM6.5Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg...
CVE-2026-10544MEDIUM6.5Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv...
CVE-2026-8913HIGH8.5A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutra...
CVE-2026-11556HIGH8.8A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file ...
CVE-2026-11555HIGH7.5A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file ...
CVE-2026-11554MEDIUM4.3A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now