2026 CVE Vulnerabilities
66,567 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34800 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/upli... |
| CVE-2026-34799 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dns... |
| CVE-2026-34798 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/ro... |
| CVE-2026-34797 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34796 | HIGH | 8.8 | 1.5% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34795 | HIGH | 8.8 | 1.5% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34794 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34793 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34792 | HIGH | 8.8 | 1.3% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34791 | HIGH | 8.8 | 1.3% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34790 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in ... |
| CVE-2026-34729 | MEDIUM | 4.8 | 0.2% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex By... |
| CVE-2026-34728 | HIGH | 8.1 | 0.7% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl... |
| CVE-2026-33641 | HIGH | 7.8 | 0.9% | Apr 2, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config... |
| CVE-2026-33544 | HIGH | 7.7 | 0.3% | Apr 2, 2026 | Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations ... |
| CVE-2026-33533 | MEDIUM | 6.5 | 0.4% | Apr 2, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (act... |
| CVE-2026-32871 | CRITICAL | 10 | 1.0% | Apr 2, 2026 | FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos... |
| CVE-2026-32629 | MEDIUM | 6.1 | 0.3% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F... |
| CVE-2026-31937 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p... |
| CVE-2026-31935 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ... |
| CVE-2026-31934 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexi... |
| CVE-2026-5338 | HIGH | 7.2 | 4.4% | Apr 2, 2026 | A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system... |
| CVE-2026-5334 | CRITICAL | 9.8 | 0.4% | Apr 2, 2026 | A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file... |
| CVE-2026-5333 | CRITICAL | 9.8 | 2.7% | Apr 2, 2026 | A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown pro... |
| CVE-2026-5332 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now