2026 CVE Vulnerabilities

66,567 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34800MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/upli...
CVE-2026-34799MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dns...
CVE-2026-34798MEDIUM5.4Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/ro...
CVE-2026-34797HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34796HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34795HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34794HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34793HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34792HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34791HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34790HIGH8.1Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in ...
CVE-2026-34729MEDIUM4.8phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex By...
CVE-2026-34728HIGH8.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl...
CVE-2026-33641HIGH7.8Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config...
CVE-2026-33544HIGH7.7Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations ...
CVE-2026-33533MEDIUM6.5Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (act...
CVE-2026-32871CRITICAL10FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos...
CVE-2026-32629MEDIUM6.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F...
CVE-2026-31937HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p...
CVE-2026-31935HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ...
CVE-2026-31934HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexi...
CVE-2026-5338HIGH7.2A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system...
CVE-2026-5334CRITICAL9.8A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file...
CVE-2026-5333CRITICAL9.8A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown pro...
CVE-2026-5332MEDIUM6.1A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now