2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5853CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t...
CVE-2026-5852CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file...
CVE-2026-5851CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of th...
CVE-2026-5850CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the ...
CVE-2026-5849CRITICAL9.8A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component...
CVE-2026-5848MEDIUM4.7A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon...
CVE-2026-5847MEDIUM4.3A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file ...
CVE-2026-5844HIGH7.3A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the compon...
CVE-2026-5842HIGH7.3A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function ...
CVE-2026-5841CRITICAL9.8A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of ...
CVE-2026-5840MEDIUM4.7A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /...
CVE-2026-5839MEDIUM4.7A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the ...
CVE-2026-5838MEDIUM4.7A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil...
CVE-2026-5742MEDIUM6.4The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. Th...
CVE-2026-4336MEDIUM6.4The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers...
CVE-2026-1830CRITICAL9.8The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1...
CVE-2026-5837HIGH7.3A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details....
CVE-2026-5836LOW2.4A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functional...
CVE-2026-5835LOW2.4A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality...
CVE-2026-5834LOW2.4A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/...
CVE-2026-5833MEDIUM5.3A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function serv...
CVE-2026-5357MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'w...
CVE-2026-4429MEDIUM6.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'fil...
CVE-2026-4124MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The ...
CVE-2026-3574MEDIUM4.4The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now