2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5853 | CRITICAL | 9.8 | 14.3% | Apr 9, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t... |
| CVE-2026-5852 | CRITICAL | 9.8 | 14.3% | Apr 9, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file... |
| CVE-2026-5851 | CRITICAL | 9.8 | 14.1% | Apr 9, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of th... |
| CVE-2026-5850 | CRITICAL | 9.8 | 16.0% | Apr 9, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the ... |
| CVE-2026-5849 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component... |
| CVE-2026-5848 | MEDIUM | 4.7 | 0.3% | Apr 9, 2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon... |
| CVE-2026-5847 | MEDIUM | 4.3 | 0.3% | Apr 9, 2026 | A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file ... |
| CVE-2026-5844 | HIGH | 7.3 | 5.1% | Apr 9, 2026 | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the compon... |
| CVE-2026-5842 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function ... |
| CVE-2026-5841 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of ... |
| CVE-2026-5840 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /... |
| CVE-2026-5839 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the ... |
| CVE-2026-5838 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil... |
| CVE-2026-5742 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. Th... |
| CVE-2026-4336 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers... |
| CVE-2026-1830 | CRITICAL | 9.8 | 3.1% | Apr 9, 2026 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1... |
| CVE-2026-5837 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.... |
| CVE-2026-5836 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functional... |
| CVE-2026-5835 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-5834 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/... |
| CVE-2026-5833 | MEDIUM | 5.3 | 0.6% | Apr 9, 2026 | A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function serv... |
| CVE-2026-5357 | MEDIUM | 6.4 | 0.3% | Apr 9, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'w... |
| CVE-2026-4429 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'fil... |
| CVE-2026-4124 | MEDIUM | 5.4 | 0.3% | Apr 9, 2026 | The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The ... |
| CVE-2026-3574 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now