2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7248CRITICAL9.4A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of t...
CVE-2026-7247HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th...
CVE-2026-7244CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiF...
CVE-2026-7243CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg...
CVE-2026-7242CRITICAL9.8A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of ...
CVE-2026-7241CRITICAL9.8A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of th...
CVE-2026-40980MEDIUM6.5In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha...
CVE-2026-40979MEDIUM6.1In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version...
CVE-2026-40978HIGH8.8SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c...
CVE-2026-7240CRITICAL9.8A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAc...
CVE-2026-7238MEDIUM4.7A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH...
CVE-2026-7237HIGH7.3A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ...
CVE-2026-7235MEDIUM5.5A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca...
CVE-2026-4911MEDIUM5.3The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 Th...
CVE-2026-4805MEDIUM6.4The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 T...
CVE-2026-41526HIGH7.8In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ...
CVE-2026-41525MEDIUM6.5KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th...
CVE-2026-40966MEDIUM5.9In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo...
CVE-2026-7234HIGH7.3A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith...
CVE-2026-7233MEDIUM6.1A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gid...
CVE-2026-7230MEDIUM4.3A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manip...
CVE-2026-7229MEDIUM6.3A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file ...
CVE-2026-5306MEDIUM5.4The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau...
CVE-2026-40967HIGH8.6In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ...
CVE-2026-40356HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now