2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-23781CRITICAL9.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded...
CVE-2026-36236CRITICAL9.8SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p...
CVE-2026-36235CRITICAL9.8A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System...
CVE-2026-36234CRITICAL9.8itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ...
CVE-2026-36233CRITICAL9.8A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme...
CVE-2026-36232CRITICAL9.8A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst...
CVE-2026-29861CRITICAL9.8PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l...
CVE-2026-6068CRITICAL9.6NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem...
CVE-2026-6057CRITICAL9.8FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remot...
CVE-2026-6029CRITICAL9.8A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccoun...
CVE-2026-6028CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpSer...
CVE-2026-6027CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRul...
CVE-2026-6026CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function se...
CVE-2026-1115CRITICAL9.6A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the...
CVE-2026-6025CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the f...
CVE-2026-6024CRITICAL9.8A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfu...
CVE-2026-5997CRITICAL9.8A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPass...
CVE-2026-5996CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the functio...
CVE-2026-5995CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow ...
CVE-2026-5994CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetC...
CVE-2026-5993CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFi...
CVE-2026-5393CRITICAL9.1Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-...
CVE-2026-5503CRITICAL9.1In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This ...
CVE-2026-34424CRITICAL9.8Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu...
CVE-2026-5264CRITICAL9.8Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now