2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7228HIGH7.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_coun...
CVE-2026-7227HIGH7.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file ...
CVE-2026-7226HIGH7.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the functi...
CVE-2026-7225HIGH7.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function d...
CVE-2026-7224HIGH7.3A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_car...
CVE-2026-6809MEDIUM6.4The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in...
CVE-2026-6725MEDIUM6.4The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' ...
CVE-2026-6551MEDIUM6.4The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' a...
CVE-2026-42510HIGH7.2OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVE-2026-40355HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c...
CVE-2026-7223HIGH7.3A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the fun...
CVE-2026-7222LOW3.5A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unk...
CVE-2026-7221HIGH7.3A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file m...
CVE-2026-7220HIGH7.3A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts a...
CVE-2026-7219HIGH7.3A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS...
CVE-2026-7218HIGH7.3A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_vali...
CVE-2026-7217MEDIUM5.5A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read...
CVE-2026-7216HIGH7.3A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. ...
CVE-2026-7215HIGH7.3A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_too...
CVE-2026-1460HIGH7.2A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zy...
CVE-2026-0711MEDIUM6.8A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions ...
CVE-2026-7214HIGH7.3A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_...
CVE-2026-7213HIGH7.3A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py ...
CVE-2026-7212HIGH7.3A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of ...
CVE-2026-7211HIGH7.3A weakness has been identified in dvladimirov MCP up to 0.1.0. The impacted element is the function GitSearchRequest of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now