2026 CVE Vulnerabilities

45,099 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-15543HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertList...
CVE-2026-15542HIGH7.3A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.g...
CVE-2026-15541HIGH7.3A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a...
CVE-2026-14165HIGH7.5An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through ...
CVE-2026-15537HIGH7.3A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown c...
CVE-2026-12582HIGH8.6The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-12275HIGH7.1The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enr...
CVE-2026-11963HIGH8.1The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membershi...
CVE-2026-9492HIGH8.5The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an ...
CVE-2026-7162HIGH7.8Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to ...
CVE-2026-15517HIGH7.3A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma...
CVE-2026-15515HIGH7A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown process...
CVE-2026-15514HIGH7.3A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCS...
CVE-2026-15506HIGH7.8A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func...
CVE-2026-10667HIGH7.8Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l...
CVE-2026-10665HIGH7.4In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou...
CVE-2026-58596HIGH8.3Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o...
CVE-2026-61875HIGH8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav...
CVE-2026-59260HIGH8.8OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t...
CVE-2026-56313HIGH8.1Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al...
CVE-2026-56308HIGH8.4Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification ...
CVE-2026-56259HIGH8.8Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to ...
CVE-2026-56241HIGH8.3Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del...
CVE-2026-56238HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint t...
CVE-2026-15498HIGH7.3A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impact...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now