2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23781 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded... |
| CVE-2026-36236 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p... |
| CVE-2026-36235 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System... |
| CVE-2026-36234 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ... |
| CVE-2026-36233 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme... |
| CVE-2026-36232 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst... |
| CVE-2026-29861 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l... |
| CVE-2026-6068 | CRITICAL | 9.6 | 0.4% | Apr 10, 2026 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem... |
| CVE-2026-6057 | CRITICAL | 9.8 | 0.9% | Apr 10, 2026 | FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remot... |
| CVE-2026-6029 | CRITICAL | 9.8 | 3.0% | Apr 10, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccoun... |
| CVE-2026-6028 | CRITICAL | 9.8 | 3.0% | Apr 10, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpSer... |
| CVE-2026-6027 | CRITICAL | 9.8 | 2.5% | Apr 10, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRul... |
| CVE-2026-6026 | CRITICAL | 9.8 | 3.0% | Apr 10, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function se... |
| CVE-2026-1115 | CRITICAL | 9.6 | 0.4% | Apr 10, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the... |
| CVE-2026-6025 | CRITICAL | 9.8 | 3.0% | Apr 10, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the f... |
| CVE-2026-6024 | CRITICAL | 9.8 | 0.7% | Apr 10, 2026 | A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfu... |
| CVE-2026-5997 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPass... |
| CVE-2026-5996 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the functio... |
| CVE-2026-5995 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow ... |
| CVE-2026-5994 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetC... |
| CVE-2026-5993 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFi... |
| CVE-2026-5393 | CRITICAL | 9.1 | 0.2% | Apr 10, 2026 | Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-... |
| CVE-2026-5503 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This ... |
| CVE-2026-34424 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu... |
| CVE-2026-5264 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now