2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7248 | CRITICAL | 9.4 | 2.2% | Apr 28, 2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of t... |
| CVE-2026-7247 | HIGH | 7.3 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th... |
| CVE-2026-7244 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiF... |
| CVE-2026-7243 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg... |
| CVE-2026-7242 | CRITICAL | 9.8 | 2.5% | Apr 28, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of ... |
| CVE-2026-7241 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of th... |
| CVE-2026-40980 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha... |
| CVE-2026-40979 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version... |
| CVE-2026-40978 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c... |
| CVE-2026-7240 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAc... |
| CVE-2026-7238 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH... |
| CVE-2026-7237 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ... |
| CVE-2026-7235 | MEDIUM | 5.5 | 0.5% | Apr 28, 2026 | A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca... |
| CVE-2026-4911 | MEDIUM | 5.3 | 0.3% | Apr 28, 2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 Th... |
| CVE-2026-4805 | MEDIUM | 6.4 | 0.2% | Apr 28, 2026 | The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 T... |
| CVE-2026-41526 | HIGH | 7.8 | 0.2% | Apr 28, 2026 | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ... |
| CVE-2026-41525 | MEDIUM | 6.5 | 0.1% | Apr 28, 2026 | KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th... |
| CVE-2026-40966 | MEDIUM | 5.9 | 0.2% | Apr 28, 2026 | In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo... |
| CVE-2026-7234 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith... |
| CVE-2026-7233 | MEDIUM | 6.1 | 0.2% | Apr 28, 2026 | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gid... |
| CVE-2026-7230 | MEDIUM | 4.3 | 0.3% | Apr 28, 2026 | A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manip... |
| CVE-2026-7229 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file ... |
| CVE-2026-5306 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau... |
| CVE-2026-40967 | HIGH | 8.6 | 0.4% | Apr 28, 2026 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ... |
| CVE-2026-40356 | HIGH | 7.5 | 0.5% | Apr 28, 2026 | In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now