2026 CVE Vulnerabilities

65,724 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5692HIGH7.3A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the fil...
CVE-2026-5691HIGH7.3A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of th...
CVE-2026-5690HIGH7.3A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the...
CVE-2026-5689HIGH7.3A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of...
CVE-2026-5688HIGH7.3A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg...
CVE-2026-5709HIGH8.8Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01...
CVE-2026-5708HIGH8.8Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud...
CVE-2026-5707HIGH8.8Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (...
CVE-2026-5687HIGH8.8A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the f...
CVE-2026-5686HIGH8.8A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic ...
CVE-2026-5685HIGH8.8A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/...
CVE-2026-5684HIGH8A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilt...
CVE-2026-35475MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET ...
CVE-2026-35474MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The re...
CVE-2026-35473MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35471CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal chec...
CVE-2026-35454MEDIUM6.5The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulner...
CVE-2026-35452MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s...
CVE-2026-35450MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint ...
CVE-2026-35449MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its...
CVE-2026-35448LOW3.7WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoin...
CVE-2026-35444MEDIUM6.1SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel ...
CVE-2026-35442HIGH8.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (...
CVE-2026-35441MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end...
CVE-2026-35413MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now