2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5996CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the functio...
CVE-2026-4977MEDIUM4.3The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerab...
CVE-2026-4664MEDIUM5.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, ...
CVE-2026-4351HIGH8.1The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to,...
CVE-2026-4305MEDIUM6.1The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2026-4057MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2026-3360HIGH7.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Ref...
CVE-2026-2712MEDIUM5.4The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability che...
CVE-2026-25203HIGH7.8Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects M...
CVE-2026-1924MEDIUM4.3The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1263MEDIUM6.4The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9....
CVE-2026-5995CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow ...
CVE-2026-5994CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetC...
CVE-2026-5993CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFi...
CVE-2026-5992HIGH8.8A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2...
CVE-2026-5991HIGH8.8A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /gof...
CVE-2026-5990HIGH8.8A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter...
CVE-2026-5989HIGH8.8A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. E...
CVE-2026-5460MEDIUM6.5A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the err...
CVE-2026-5448MEDIUM4.3X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d...
CVE-2026-5393CRITICAL9.1Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-...
CVE-2026-5392MEDIUM5.4Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound...
CVE-2026-5988HIGH8.8A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetW...
CVE-2026-5987MEDIUM4.7A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree...
CVE-2026-5986MEDIUM5.5A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now