2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-18613CRITICAL9.8A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t...
CVE-2026-18612CRITICAL9.8A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p...
CVE-2026-41452CRITICAL9.8Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated...
CVE-2026-39932CRITICAL9.1OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl...
CVE-2026-18602CRITICAL9.8A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf...
CVE-2026-18248CRITICAL9.1@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont...
CVE-2026-9487CRITICAL9.1XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, ...
CVE-2026-9390CRITICAL9.1XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si...
CVE-2026-69085CRITICAL10SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s...
CVE-2026-69084CRITICAL10SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement...
CVE-2026-69083CRITICAL10SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable...
CVE-2026-68587CRITICAL9.2SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea...
CVE-2026-68586CRITICAL9.2SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints...
CVE-2026-68584CRITICAL9.2SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end...
CVE-2026-64827CRITICAL9.8Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp...
CVE-2026-18601CRITICAL9.8A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi...
CVE-2026-18108CRITICAL9.8Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr...
CVE-2026-2346CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ...
CVE-2026-18574CRITICAL9.3An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se...
CVE-2026-33591CRITICAL10A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security r...
CVE-2026-18589CRITICAL9.8A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file na...
CVE-2026-18588CRITICAL9.8A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi...
CVE-2026-16534CRITICAL9.1The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and...
CVE-2026-16532CRITICAL9.1The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using ...
CVE-2026-16300CRITICAL9.8The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now