2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7159HIGH7.3A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_document...
CVE-2026-7191HIGH8.6Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may all...
CVE-2026-7158HIGH7.3A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected...
CVE-2026-7157HIGH7.3A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulner...
CVE-2026-7156CRITICAL9.8A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /c...
CVE-2026-7155CRITICAL9.8A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPa...
CVE-2026-7154CRITICAL9.8A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of...
CVE-2026-5362MEDIUM5.4An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed...
CVE-2026-3087HIGH7.5If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th...
CVE-2026-29971MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U...
CVE-2026-7153CRITICAL9.8A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMin...
CVE-2026-7152CRITICAL9.8A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf...
CVE-2026-7151HIGH8.8A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6...
CVE-2026-6741HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-5394HIGH7An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled ...
CVE-2026-7150MEDIUM6.3A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the ...
CVE-2026-7149HIGH7.3A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerabilit...
CVE-2026-7148MEDIUM6.3A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut...
CVE-2026-7147HIGH7.3A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functiona...
CVE-2026-40970MEDIUM6.8When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat...
CVE-2026-35903CRITICAL9.8MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP s...
CVE-2026-35902MEDIUM6.2The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att...
CVE-2026-35901MEDIUM4.4A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac...
CVE-2026-32655HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l...
CVE-2026-31256HIGH7.5A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now