2026 CVE Vulnerabilities
65,752 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20431 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha... |
| CVE-2026-5719 | MEDIUM | 6.3 | 0.2% | Apr 7, 2026 | A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /... |
| CVE-2026-5705 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f... |
| CVE-2026-5692 | HIGH | 7.3 | 1.4% | Apr 7, 2026 | A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the fil... |
| CVE-2026-5691 | HIGH | 7.3 | 1.2% | Apr 6, 2026 | A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of th... |
| CVE-2026-5690 | HIGH | 7.3 | 1.5% | Apr 6, 2026 | A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the... |
| CVE-2026-5689 | HIGH | 7.3 | 1.5% | Apr 6, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of... |
| CVE-2026-5688 | HIGH | 7.3 | 1.4% | Apr 6, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg... |
| CVE-2026-5709 | HIGH | 8.8 | 1.1% | Apr 6, 2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01... |
| CVE-2026-5708 | HIGH | 8.8 | 0.8% | Apr 6, 2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud... |
| CVE-2026-5707 | HIGH | 8.8 | 1.0% | Apr 6, 2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (... |
| CVE-2026-5687 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the f... |
| CVE-2026-5686 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic ... |
| CVE-2026-5685 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/... |
| CVE-2026-5684 | HIGH | 8 | 0.6% | Apr 6, 2026 | A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilt... |
| CVE-2026-35475 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET ... |
| CVE-2026-35474 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The re... |
| CVE-2026-35473 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35471 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal chec... |
| CVE-2026-35454 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulner... |
| CVE-2026-35452 | MEDIUM | 5.3 | 0.4% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s... |
| CVE-2026-35450 | MEDIUM | 5.3 | 0.4% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint ... |
| CVE-2026-35449 | MEDIUM | 5.3 | 0.3% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its... |
| CVE-2026-35448 | LOW | 3.7 | 0.3% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoin... |
| CVE-2026-35444 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now