2026 CVE Vulnerabilities
64,618 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9485 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un... |
| CVE-2026-9484 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is... |
| CVE-2026-48849 | MEDIUM | 4.4 | 0.2% | May 25, 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu... |
| CVE-2026-48848 | HIGH | 7.2 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascadi... |
| CVE-2026-48847 | LOW | 3.7 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi... |
| CVE-2026-48846 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a... |
| CVE-2026-48845 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U... |
| CVE-2026-48844 | HIGH | 7.5 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o... |
| CVE-2026-48843 | HIGH | 7.2 | 0.3% | May 25, 2026 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) s... |
| CVE-2026-48842 | HIGH | 8.1 | 0.9% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query ... |
| CVE-2026-24546 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2026-9483 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the... |
| CVE-2026-9482 | HIGH | 8.8 | 0.6% | May 25, 2026 | A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSD... |
| CVE-2026-9481 | HIGH | 8.8 | 0.6% | May 25, 2026 | A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This... |
| CVE-2026-9480 | HIGH | 8.8 | 0.6% | May 25, 2026 | A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /go... |
| CVE-2026-9479 | HIGH | 8.8 | 0.6% | May 25, 2026 | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of... |
| CVE-2026-9478 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the... |
| CVE-2026-9477 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDe... |
| CVE-2026-9476 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPassw... |
| CVE-2026-9475 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the f... |
| CVE-2026-9474 | HIGH | 7.3 | 0.3% | May 25, 2026 | A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Af... |
| CVE-2026-9473 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileConten... |
| CVE-2026-9472 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the funct... |
| CVE-2026-9471 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This ... |
| CVE-2026-27768 | MEDIUM | 6.6 | 0.3% | May 25, 2026 | SQL Injection affecting the Access Manager role. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now