2026 CVE Vulnerabilities

66,948 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4317CRITICAL9.3SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co...
CVE-2026-5201HIGH7.5A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade...
CVE-2026-5196MEDIUM6.3A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi...
CVE-2026-5195HIGH7.3A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ...
CVE-2026-3107MEDIUM5.4Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password impo...
CVE-2026-3106MEDIUM5.4Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionalit...
CVE-2026-5186MEDIUM5.3A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb...
CVE-2026-5185MEDIUM5.3A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t...
CVE-2026-5184HIGH8.8A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file...
CVE-2026-3881MEDIUM5.8The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, whic...
CVE-2026-5183CRITICAL9.8A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ...
CVE-2026-5182HIGH7.3A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teach...
CVE-2026-34881MEDIUM5OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use...
CVE-2026-1877MEDIUM6.1The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1834MEDIUM6.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2026-5181MEDIUM6.3A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un...
CVE-2026-5180HIGH7.3A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code o...
CVE-2026-5179HIGH7.3A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of th...
CVE-2026-4146MEDIUM6.1The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter ...
CVE-2026-1797MEDIUM5.3The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2026-1710MEDIUM6.5The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2026-5178HIGH8.8A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the func...
CVE-2026-5177HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function...
CVE-2026-34073MEDIUM5.3cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version...
CVE-2026-34070HIGH7.5LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now