2026 CVE Vulnerabilities

64,618 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9485LOW3.5A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un...
CVE-2026-9484MEDIUM6.3A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is...
CVE-2026-48849MEDIUM4.4In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu...
CVE-2026-48848HIGH7.2Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascadi...
CVE-2026-48847LOW3.7Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi...
CVE-2026-48846MEDIUM6.5In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a...
CVE-2026-48845MEDIUM6.5In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U...
CVE-2026-48844HIGH7.5Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o...
CVE-2026-48843HIGH7.2Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) s...
CVE-2026-48842HIGH8.1Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query ...
CVE-2026-24546MEDIUM5.3Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se...
CVE-2026-9483MEDIUM6.3A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the...
CVE-2026-9482HIGH8.8A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSD...
CVE-2026-9481HIGH8.8A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This...
CVE-2026-9480HIGH8.8A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /go...
CVE-2026-9479HIGH8.8A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of...
CVE-2026-9478CRITICAL9.8A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the...
CVE-2026-9477CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDe...
CVE-2026-9476CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPassw...
CVE-2026-9475CRITICAL9.8A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the f...
CVE-2026-9474HIGH7.3A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Af...
CVE-2026-9473MEDIUM6.3A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileConten...
CVE-2026-9472MEDIUM6.3A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the funct...
CVE-2026-9471LOW3.5A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This ...
CVE-2026-27768MEDIUM6.6SQL Injection affecting the Access Manager role.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now