2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18613 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t... |
| CVE-2026-18612 | CRITICAL | 9.8 | 2.2% | Aug 3, 2026 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p... |
| CVE-2026-41452 | CRITICAL | 9.8 | — | Aug 3, 2026 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated... |
| CVE-2026-39932 | CRITICAL | 9.1 | — | Aug 3, 2026 | OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl... |
| CVE-2026-18602 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf... |
| CVE-2026-18248 | CRITICAL | 9.1 | — | Aug 3, 2026 | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont... |
| CVE-2026-9487 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, ... |
| CVE-2026-9390 | CRITICAL | 9.1 | 0.3% | Aug 3, 2026 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si... |
| CVE-2026-69085 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s... |
| CVE-2026-69084 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement... |
| CVE-2026-69083 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable... |
| CVE-2026-68587 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea... |
| CVE-2026-68586 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints... |
| CVE-2026-68584 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end... |
| CVE-2026-64827 | CRITICAL | 9.8 | 0.4% | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp... |
| CVE-2026-18601 | CRITICAL | 9.8 | 2.4% | Aug 3, 2026 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi... |
| CVE-2026-18108 | CRITICAL | 9.8 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr... |
| CVE-2026-2346 | CRITICAL | 9.8 | — | Aug 3, 2026 | Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ... |
| CVE-2026-18574 | CRITICAL | 9.3 | 1.0% | Aug 3, 2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se... |
| CVE-2026-33591 | CRITICAL | 10 | — | Aug 3, 2026 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security r... |
| CVE-2026-18589 | CRITICAL | 9.8 | 0.6% | Aug 3, 2026 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file na... |
| CVE-2026-18588 | CRITICAL | 9.8 | 0.6% | Aug 3, 2026 | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi... |
| CVE-2026-16534 | CRITICAL | 9.1 | 0.1% | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and... |
| CVE-2026-16532 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using ... |
| CVE-2026-16300 | CRITICAL | 9.8 | 0.1% | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now