2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6154 | CRITICAL | 9.8 | 1.8% | Apr 13, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWi... |
| CVE-2026-6140 | CRITICAL | 9.8 | 2.2% | Apr 13, 2026 | A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the ... |
| CVE-2026-6139 | CRITICAL | 9.8 | 1.8% | Apr 13, 2026 | A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of ... |
| CVE-2026-6138 | CRITICAL | 9.8 | 1.8% | Apr 13, 2026 | A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg ... |
| CVE-2026-6132 | CRITICAL | 9.8 | 2.2% | Apr 12, 2026 | A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCf... |
| CVE-2026-6131 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTr... |
| CVE-2026-40393 | CRITICAL | 9.8 | 0.3% | Apr 12, 2026 | In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-... |
| CVE-2026-6116 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiag... |
| CVE-2026-6115 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin... |
| CVE-2026-6114 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetwork... |
| CVE-2026-6113 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t... |
| CVE-2026-6112 | CRITICAL | 9.8 | 1.8% | Apr 12, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the fil... |
| CVE-2026-6110 | CRITICAL | 9.8 | 0.4% | Apr 12, 2026 | A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of t... |
| CVE-2026-31845 | CRITICAL | 9.3 | 0.5% | Apr 11, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma ... |
| CVE-2026-5059 | CRITICAL | 9.8 | 1.9% | Apr 11, 2026 | aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers... |
| CVE-2026-5058 | CRITICAL | 9.8 | 1.8% | Apr 11, 2026 | aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec... |
| CVE-2026-4149 | CRITICAL | 9.8 | 1.0% | Apr 11, 2026 | Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2026-40190 | CRITICAL | 9.8 | 0.2% | Apr 10, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScri... |
| CVE-2026-40189 | CRITICAL | 9.8 | 0.7% | Apr 10, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/ba... |
| CVE-2026-30232 | CRITICAL | 9.6 | 0.2% | Apr 10, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-33707 | CRITICAL | 9.8 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism gener... |
| CVE-2026-33698 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code fr... |
| CVE-2026-5483 | CRITICAL | 9.9 | 0.5% | Apr 10, 2026 | A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Ha... |
| CVE-2026-35652 | CRITICAL | 9.1 | 0.4% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows no... |
| CVE-2026-34727 | CRITICAL | 9.1 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now