2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40974CRITICAL9.8Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to...
CVE-2026-40973HIGH7A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe...
CVE-2026-40972HIGH7.5An attacker on the same network as the remote application may be able to utilize a timing attack to discover information...
CVE-2026-27785HIGH8.8Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
CVE-2026-7194HIGH7.3A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown functi...
CVE-2026-7183MEDIUM5.5A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess...
CVE-2026-7179MEDIUM5.3A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul...
CVE-2026-40971CRITICAL9.1When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w...
CVE-2026-28747HIGH7.3A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization ...
CVE-2026-7178HIGH7.3A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file a...
CVE-2026-7177HIGH7.3A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function prox...
CVE-2026-7160HIGH8.8A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boafor...
CVE-2026-7159HIGH7.3A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_document...
CVE-2026-7191HIGH8.6Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may all...
CVE-2026-7158HIGH7.3A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected...
CVE-2026-7157HIGH7.3A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulner...
CVE-2026-7156CRITICAL9.8A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /c...
CVE-2026-7155CRITICAL9.8A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPa...
CVE-2026-7154CRITICAL9.8A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of...
CVE-2026-5362MEDIUM5.4An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed...
CVE-2026-3087HIGH7.5If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th...
CVE-2026-29971MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U...
CVE-2026-7153CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMin...
CVE-2026-7152CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf...
CVE-2026-7151HIGH8.8A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now