2026 CVE Vulnerabilities

65,754 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35020——Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the atta...
CVE-2026-5678HIGH7.3A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setSchedul...
CVE-2026-5677HIGH7.3A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the...
CVE-2026-5676HIGH7.3A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of ...
CVE-2026-33817——Rejected reason: CVE confirmed to be a false positive
CVE-2026-0049MEDIUM6.2In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti...
CVE-2026-5675MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /...
CVE-2026-5672HIGH7.3A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown f...
CVE-2026-5671MEDIUM4.3A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im...
CVE-2026-35470HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_...
CVE-2026-35209HIGH7.5defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pa...
CVE-2026-35177HIGH7.1Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo...
CVE-2026-35175MEDIUM6.5Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugi...
CVE-2026-35174HIGH7.2Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin...
CVE-2026-35173MEDIUM6.5Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post...
CVE-2026-35171CRITICAL9.8Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path t...
CVE-2026-35167HIGH8.1Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core....
CVE-2026-35166MEDIUM5.4Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML re...
CVE-2026-35164HIGH8.8Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload...
CVE-2026-35052CRITICAL9.8D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3...
CVE-2026-35050HIGH8.8text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save ...
CVE-2026-35047CRITICAL9.8Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allo...
CVE-2026-35046MEDIUM5.4Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tan...
CVE-2026-35045HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the...
CVE-2026-35044CRITICAL9.6BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now