2026 CVE Vulnerabilities
65,368 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5996 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the functio... |
| CVE-2026-4977 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerab... |
| CVE-2026-4664 | MEDIUM | 5.3 | 0.7% | Apr 10, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, ... |
| CVE-2026-4351 | HIGH | 8.1 | 0.4% | Apr 10, 2026 | The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to,... |
| CVE-2026-4305 | MEDIUM | 6.1 | 0.3% | Apr 10, 2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2026-4057 | MEDIUM | 4.3 | 0.4% | Apr 10, 2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2026-3360 | HIGH | 7.5 | 0.6% | Apr 10, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Ref... |
| CVE-2026-2712 | MEDIUM | 5.4 | 0.4% | Apr 10, 2026 | The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability che... |
| CVE-2026-25203 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects M... |
| CVE-2026-1924 | MEDIUM | 4.3 | 0.2% | Apr 10, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1263 | MEDIUM | 6.4 | 0.3% | Apr 10, 2026 | The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.... |
| CVE-2026-5995 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow ... |
| CVE-2026-5994 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetC... |
| CVE-2026-5993 | CRITICAL | 9.8 | 1.8% | Apr 10, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFi... |
| CVE-2026-5992 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2... |
| CVE-2026-5991 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /gof... |
| CVE-2026-5990 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter... |
| CVE-2026-5989 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. E... |
| CVE-2026-5460 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the err... |
| CVE-2026-5448 | MEDIUM | 4.3 | 0.1% | Apr 10, 2026 | X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d... |
| CVE-2026-5393 | CRITICAL | 9.1 | 0.2% | Apr 10, 2026 | Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-... |
| CVE-2026-5392 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound... |
| CVE-2026-5988 | HIGH | 8.8 | 0.5% | Apr 9, 2026 | A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetW... |
| CVE-2026-5987 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree... |
| CVE-2026-5986 | MEDIUM | 5.5 | 0.4% | Apr 9, 2026 | A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now