2026 CVE Vulnerabilities
64,922 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7159 | HIGH | 7.3 | 0.4% | Apr 27, 2026 | A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_document... |
| CVE-2026-7191 | HIGH | 8.6 | 0.4% | Apr 27, 2026 | Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may all... |
| CVE-2026-7158 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected... |
| CVE-2026-7157 | HIGH | 7.3 | 1.3% | Apr 27, 2026 | A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulner... |
| CVE-2026-7156 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /c... |
| CVE-2026-7155 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPa... |
| CVE-2026-7154 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of... |
| CVE-2026-5362 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed... |
| CVE-2026-3087 | HIGH | 7.5 | 0.6% | Apr 27, 2026 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th... |
| CVE-2026-29971 | MEDIUM | 6.1 | 0.3% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U... |
| CVE-2026-7153 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMin... |
| CVE-2026-7152 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCf... |
| CVE-2026-7151 | HIGH | 8.8 | 0.6% | Apr 27, 2026 | A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6... |
| CVE-2026-6741 | HIGH | 8.8 | 0.3% | Apr 27, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-5394 | HIGH | 7 | 0.3% | Apr 27, 2026 | An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled ... |
| CVE-2026-7150 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the ... |
| CVE-2026-7149 | HIGH | 7.3 | 0.4% | Apr 27, 2026 | A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerabilit... |
| CVE-2026-7148 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut... |
| CVE-2026-7147 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functiona... |
| CVE-2026-40970 | MEDIUM | 6.8 | 0.1% | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat... |
| CVE-2026-35903 | CRITICAL | 9.8 | 0.5% | Apr 27, 2026 | MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP s... |
| CVE-2026-35902 | MEDIUM | 6.2 | 0.2% | Apr 27, 2026 | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att... |
| CVE-2026-35901 | MEDIUM | 4.4 | 0.2% | Apr 27, 2026 | A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac... |
| CVE-2026-32655 | HIGH | 7.8 | 0.1% | Apr 27, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l... |
| CVE-2026-31256 | HIGH | 7.5 | 0.4% | Apr 27, 2026 | A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now