2026 CVE Vulnerabilities

66,804 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0397MEDIUM4.3When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged...
CVE-2026-0396MEDIUM4.3An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNS...
CVE-2026-4400MEDIUM6.5Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of ot...
CVE-2026-4399HIGH7.5Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions ...
CVE-2026-34887MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubi...
CVE-2026-5197MEDIUM6.3A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of...
CVE-2026-4317CRITICAL9.3SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co...
CVE-2026-5201HIGH7.5A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade...
CVE-2026-5196MEDIUM6.3A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi...
CVE-2026-5195HIGH7.3A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ...
CVE-2026-3107MEDIUM5.4Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password impo...
CVE-2026-3106MEDIUM5.4Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionalit...
CVE-2026-5186MEDIUM5.3A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb...
CVE-2026-5185MEDIUM5.3A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t...
CVE-2026-5184HIGH8.8A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file...
CVE-2026-3881MEDIUM5.8The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, whic...
CVE-2026-5183CRITICAL9.8A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ...
CVE-2026-5182HIGH7.3A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teach...
CVE-2026-34881MEDIUM5OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use...
CVE-2026-1877MEDIUM6.1The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1834MEDIUM6.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2026-5181MEDIUM6.3A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un...
CVE-2026-5180HIGH7.3A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code o...
CVE-2026-5179HIGH7.3A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of th...
CVE-2026-4146MEDIUM6.1The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now