2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6026CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function se...
CVE-2026-4432MEDIUM6.5The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_t...
CVE-2026-28704HIGH8.4Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbit...
CVE-2026-1115CRITICAL9.6A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the...
CVE-2026-6025CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the f...
CVE-2026-6024CRITICAL9.8A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfu...
CVE-2026-6016HIGH8.8A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/W...
CVE-2026-6015HIGH8.8A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/Qui...
CVE-2026-5477HIGH7.5An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The functi...
CVE-2026-6014HIGH8.8A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formA...
CVE-2026-6013HIGH8.8A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /g...
CVE-2026-6012HIGH8.8A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file...
CVE-2026-6011HIGH8.1A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the ...
CVE-2026-4482MEDIUM5.5The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windo...
CVE-2026-6010MEDIUM6.3A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknow...
CVE-2026-6007MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the fi...
CVE-2026-6006MEDIUM6.3A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown...
CVE-2026-6005MEDIUM6.3A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function...
CVE-2026-5501HIGH8.1wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is...
CVE-2026-5500MEDIUM5.9wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received a...
CVE-2026-5479HIGH8.1In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher fi...
CVE-2026-5466HIGH8.1wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_...
CVE-2026-5188HIGH8.1An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certific...
CVE-2026-2305MEDIUM6.4The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_cod...
CVE-2026-6004HIGH7.3A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now