2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-6154CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWi...
CVE-2026-6140CRITICAL9.8A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the ...
CVE-2026-6139CRITICAL9.8A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of ...
CVE-2026-6138CRITICAL9.8A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg ...
CVE-2026-6132CRITICAL9.8A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCf...
CVE-2026-6131CRITICAL9.8A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTr...
CVE-2026-40393CRITICAL9.8In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-...
CVE-2026-6116CRITICAL9.8A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiag...
CVE-2026-6115CRITICAL9.8A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin...
CVE-2026-6114CRITICAL9.8A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetwork...
CVE-2026-6113CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t...
CVE-2026-6112CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the fil...
CVE-2026-6110CRITICAL9.8A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of t...
CVE-2026-31845CRITICAL9.3A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma ...
CVE-2026-5059CRITICAL9.8aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
CVE-2026-5058CRITICAL9.8aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec...
CVE-2026-4149CRITICAL9.8Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2026-40190CRITICAL9.8LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScri...
CVE-2026-40189CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/ba...
CVE-2026-30232CRITICAL9.6Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-33707CRITICAL9.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism gener...
CVE-2026-33698CRITICAL9.8Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code fr...
CVE-2026-5483CRITICAL9.9A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Ha...
CVE-2026-35652CRITICAL9.1OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows no...
CVE-2026-34727CRITICAL9.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now