2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-38940MEDIUM6.1Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2026-38939MEDIUM6.1Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code...
CVE-2026-36960HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1....
CVE-2026-36759MEDIUM6.5A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat...
CVE-2026-36758MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at...
CVE-2026-36756MEDIUM5.4A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a...
CVE-2026-36340HIGH8.1An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e...
CVE-2026-34998——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-34997——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-34996——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-34995——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-34994——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-7500MEDIUM5.4When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled...
CVE-2026-36959HIGH7.5U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T...
CVE-2026-36958HIGH7.5A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concur...
CVE-2026-36957HIGH7.5Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI h...
CVE-2026-36956HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireles...
CVE-2026-7246HIGH7.2This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Clic...
CVE-2026-7163MEDIUM5.5A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul...
CVE-2026-2892HIGH7.5The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including...
CVE-2026-7402HIGH8.1Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This ...
CVE-2026-7399HIGH8.1Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege...
CVE-2026-7382MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized ...
CVE-2026-5080MEDIUM5.9Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate...
CVE-2026-41882HIGH7.5In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now