2026 CVE Vulnerabilities
64,618 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9518 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function a... |
| CVE-2026-4795 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware ... |
| CVE-2026-42497 | HIGH | 7.5 | 0.4% | May 26, 2026 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo... |
| CVE-2026-42496 | CRITICAL | 9.1 | 0.4% | May 26, 2026 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire... |
| CVE-2026-9517 | HIGH | 7.3 | 0.4% | May 26, 2026 | A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown fun... |
| CVE-2026-9515 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of t... |
| CVE-2026-8376 | CRITICAL | 9.8 | 0.4% | May 26, 2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow w... |
| CVE-2026-9514 | MEDIUM | 6.3 | 1.8% | May 25, 2026 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of th... |
| CVE-2026-9513 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the fi... |
| CVE-2026-9512 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordC... |
| CVE-2026-48837 | HIGH | 8.5 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements... |
| CVE-2026-45438 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured ... |
| CVE-2026-45435 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ... |
| CVE-2026-45217 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommer... |
| CVE-2026-45216 | HIGH | 8.8 | 0.4% | May 25, 2026 | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects... |
| CVE-2026-45209 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access... |
| CVE-2026-42776 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-42774 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi... |
| CVE-2026-42773 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn... |
| CVE-2026-42763 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue aff... |
| CVE-2026-39436 | HIGH | 7.1 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe... |
| CVE-2026-32389 | MEDIUM | 5.4 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-24937 | HIGH | 7.2 | 0.4% | May 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows ... |
| CVE-2026-9511 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-... |
| CVE-2026-9504 | LOW | 3.3 | 0.2% | May 25, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now