2026 CVE Vulnerabilities
64,922 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31255 | CRITICAL | 9.8 | 1.1% | Apr 27, 2026 | A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/S... |
| CVE-2026-7146 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b49... |
| CVE-2026-7145 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C... |
| CVE-2026-7144 | MEDIUM | 4.3 | 0.2% | Apr 27, 2026 | A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown functi... |
| CVE-2026-7143 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown funct... |
| CVE-2026-31691 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When ... |
| CVE-2026-31690 | HIGH | 7.8 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standa... |
| CVE-2026-31689 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc()... |
| CVE-2026-31688 | — | — | — | Apr 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-31687 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Comm... |
| CVE-2026-31686 | HIGH | 7.8 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_fre... |
| CVE-2026-25908 | HIGH | 7.8 | 0.1% | Apr 27, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne... |
| CVE-2026-7142 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the f... |
| CVE-2026-7141 | MEDIUM | 5.6 | 0.3% | Apr 27, 2026 | A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v... |
| CVE-2026-7140 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file ... |
| CVE-2026-7139 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the fi... |
| CVE-2026-38936 | MEDIUM | 6.1 | 0.2% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php v... |
| CVE-2026-38935 | MEDIUM | 6.1 | 0.2% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the do... |
| CVE-2026-38934 | HIGH | 8.8 | 0.2% | Apr 27, 2026 | Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker... |
| CVE-2026-30462 | MEDIUM | 4.3 | 0.5% | Apr 27, 2026 | A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a dire... |
| CVE-2026-30346 | MEDIUM | 4.3 | 0.3% | Apr 27, 2026 | An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to ... |
| CVE-2026-7138 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg ... |
| CVE-2026-7137 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorage... |
| CVE-2026-7136 | CRITICAL | 9.8 | 1.8% | Apr 27, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg... |
| CVE-2026-7135 | MEDIUM | 5.3 | 0.1% | Apr 27, 2026 | A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now