2026 CVE Vulnerabilities

64,618 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9518MEDIUM4.3A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function a...
CVE-2026-4795MEDIUM6.5A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware ...
CVE-2026-42497HIGH7.5Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo...
CVE-2026-42496CRITICAL9.1Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire...
CVE-2026-9517HIGH7.3A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown fun...
CVE-2026-9515MEDIUM6.3A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of t...
CVE-2026-8376CRITICAL9.8Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow w...
CVE-2026-9514MEDIUM6.3A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of th...
CVE-2026-9513MEDIUM6.3A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the fi...
CVE-2026-9512MEDIUM6.3A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordC...
CVE-2026-48837HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements...
CVE-2026-45438HIGH7.5Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured ...
CVE-2026-45435MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ...
CVE-2026-45217MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommer...
CVE-2026-45216HIGH8.8Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects...
CVE-2026-45209HIGH7.5Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access...
CVE-2026-42776MEDIUM6.3Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access C...
CVE-2026-42774CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi...
CVE-2026-42773CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn...
CVE-2026-42763MEDIUM6.5Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue aff...
CVE-2026-39436HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe...
CVE-2026-32389MEDIUM5.4Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-24937HIGH7.2Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows ...
CVE-2026-9511MEDIUM6.3A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-...
CVE-2026-9504LOW3.3A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now