2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40974 | CRITICAL | 9.8 | 0.2% | Apr 28, 2026 | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to... |
| CVE-2026-40973 | HIGH | 7 | 0.1% | Apr 28, 2026 | A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe... |
| CVE-2026-40972 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | An attacker on the same network as the remote application may be able to utilize a timing attack to discover information... |
| CVE-2026-27785 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. |
| CVE-2026-7194 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown functi... |
| CVE-2026-7183 | MEDIUM | 5.5 | 0.4% | Apr 27, 2026 | A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess... |
| CVE-2026-7179 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul... |
| CVE-2026-40971 | CRITICAL | 9.1 | 0.2% | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w... |
| CVE-2026-28747 | HIGH | 7.3 | 0.2% | Apr 27, 2026 | A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization ... |
| CVE-2026-7178 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file a... |
| CVE-2026-7177 | HIGH | 7.3 | 0.4% | Apr 27, 2026 | A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function prox... |
| CVE-2026-7160 | HIGH | 8.8 | 3.3% | Apr 27, 2026 | A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boafor... |
| CVE-2026-7159 | HIGH | 7.3 | 0.4% | Apr 27, 2026 | A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_document... |
| CVE-2026-7191 | HIGH | 8.6 | 0.4% | Apr 27, 2026 | Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may all... |
| CVE-2026-7158 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected... |
| CVE-2026-7157 | HIGH | 7.3 | 1.3% | Apr 27, 2026 | A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulner... |
| CVE-2026-7156 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /c... |
| CVE-2026-7155 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPa... |
| CVE-2026-7154 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of... |
| CVE-2026-5362 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed... |
| CVE-2026-3087 | HIGH | 7.5 | 0.6% | Apr 27, 2026 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th... |
| CVE-2026-29971 | MEDIUM | 6.1 | 0.3% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U... |
| CVE-2026-7153 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMin... |
| CVE-2026-7152 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf... |
| CVE-2026-7151 | HIGH | 8.8 | 0.6% | Apr 27, 2026 | A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now