2026 CVE Vulnerabilities

66,522 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34805MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dn...
CVE-2026-34804MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/r...
CVE-2026-34803MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/c...
CVE-2026-34802MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter ...
CVE-2026-34801MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhc...
CVE-2026-34800MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/upli...
CVE-2026-34799MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dns...
CVE-2026-34798MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/ro...
CVE-2026-34797HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34796HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34795HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34794HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34793HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34792HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34791HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34790HIGH8.1Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in ...
CVE-2026-34729MEDIUM4.8phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex By...
CVE-2026-34728HIGH8.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl...
CVE-2026-33641HIGH7.8Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config...
CVE-2026-33544HIGH7.7Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations ...
CVE-2026-33533MEDIUM6.5Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (act...
CVE-2026-32871CRITICAL10FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos...
CVE-2026-32629MEDIUM6.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F...
CVE-2026-31937HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p...
CVE-2026-31935HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now