2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31255CRITICAL9.8A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/S...
CVE-2026-7146HIGH7.3A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b49...
CVE-2026-7145MEDIUM5.4A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C...
CVE-2026-7144MEDIUM4.3A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown functi...
CVE-2026-7143MEDIUM6.3A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown funct...
CVE-2026-31691MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When ...
CVE-2026-31690HIGH7.8In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standa...
CVE-2026-31689MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc()...
CVE-2026-31688——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-31687MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Comm...
CVE-2026-31686HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_fre...
CVE-2026-25908HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne...
CVE-2026-7142MEDIUM6.3A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the f...
CVE-2026-7141MEDIUM5.6A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v...
CVE-2026-7140CRITICAL9.8A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file ...
CVE-2026-7139CRITICAL9.8A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the fi...
CVE-2026-38936MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php v...
CVE-2026-38935MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the do...
CVE-2026-38934HIGH8.8Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker...
CVE-2026-30462MEDIUM4.3A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a dire...
CVE-2026-30346MEDIUM4.3An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to ...
CVE-2026-7138CRITICAL9.8A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg ...
CVE-2026-7137CRITICAL9.8A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorage...
CVE-2026-7136CRITICAL9.8A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg...
CVE-2026-7135MEDIUM5.3A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now