2026 CVE Vulnerabilities

67,075 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28528MEDIUM4.6BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET...
CVE-2026-28527HIGH7.3BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY...
CVE-2026-28526MEDIUM5.7BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA...
CVE-2026-4315MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t...
CVE-2026-4266MEDIUM6.7An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to...
CVE-2026-4425——Rejected reason: Reserved for EastLink case, but no need for CVE anymore
CVE-2026-1612MEDIUM6.9AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket...
CVE-2026-5128——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-5121HIGH7.5A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ...
CVE-2026-4416HIGH8.5The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate...
CVE-2026-4415CRITICAL9.8Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena...
CVE-2026-3945HIGH8.7An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ...
CVE-2026-2328HIGH7.5An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i...
CVE-2026-25704MEDIUM5.8A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greete...
CVE-2026-5119HIGH8.2A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies ...
CVE-2026-5107MEDIUM4.2A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file ...
CVE-2026-5106MEDIUM4.8A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file...
CVE-2026-5105HIGH8.8A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassC...
CVE-2026-5104HIGH8.8A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStatic...
CVE-2026-5103HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of ...
CVE-2026-3124HIGH7.5The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i...
CVE-2026-5102HIGH8.8A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function s...
CVE-2026-2370HIGH8.8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2026-5101HIGH8.8A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the fil...
CVE-2026-4176CRITICAL9.8Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now