2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22077MEDIUM5.6OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access res...
CVE-2026-7094HIGH7.3A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Af...
CVE-2026-7093MEDIUM6.3A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown f...
CVE-2026-7092MEDIUM6.3A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the fi...
CVE-2026-7091MEDIUM6.3A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user...
CVE-2026-42371MEDIUM5.1uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in ...
CVE-2026-3008MEDIUM6.6Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address informati...
CVE-2026-7090LOW2.4A vulnerability was detected in code-projects Chat System 1.0. This affects an unknown function of the file /admin/send_...
CVE-2026-7089MEDIUM4.3A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown ...
CVE-2026-7088HIGH7.3A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk...
CVE-2026-7087HIGH7.3A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown fu...
CVE-2026-7086MEDIUM4.3A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl...
CVE-2026-7085MEDIUM5A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of th...
CVE-2026-7084MEDIUM6.3A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/s...
CVE-2026-7083MEDIUM4.7A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function q...
CVE-2026-7082HIGH8.8A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file ...
CVE-2026-7081HIGH8.8A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDh...
CVE-2026-3868HIGH8.7An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be...
CVE-2026-3867MEDIUM6An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownershi...
CVE-2026-7106HIGH8.8The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to a...
CVE-2026-7080HIGH8.8A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the f...
CVE-2026-7079HIGH8.8A weakness has been identified in Tenda F456 1.0.0.5. This affects the function fromAdvSetWan of the file /goform/AdvSet...
CVE-2026-7078HIGH8.8A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the fil...
CVE-2026-7077HIGH7.3A vulnerability was identified in itsourcecode Courier Management System 1.0. The affected element is an unknown functio...
CVE-2026-3006HIGH7Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now