2026 CVE Vulnerabilities

67,095 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5041MEDIUM4.7A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the fu...
CVE-2026-5037LOW3.3A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c ...
CVE-2026-5036HIGH8.8A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the f...
CVE-2026-5035CRITICAL9.8A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo...
CVE-2026-5034CRITICAL9.8A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th...
CVE-2026-5033CRITICAL9.8A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi...
CVE-2026-5031MEDIUM4.3A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_...
CVE-2026-5030CRITICAL9.8A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos...
CVE-2026-5024HIGH8.8A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formS...
CVE-2026-5023MEDIUM5.3A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner...
CVE-2026-5021HIGH8.8A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserS...
CVE-2026-2602MEDIUM6.4The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter...
CVE-2026-5020CRITICAL9.8A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNotice...
CVE-2026-4851CRITICAL9.8GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine...
CVE-2026-5019CRITICAL9.8A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability...
CVE-2026-5018CRITICAL9.8A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the fil...
CVE-2026-5017CRITICAL9.8A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of t...
CVE-2026-5016HIGH7.3A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the ...
CVE-2026-5015MEDIUM4.3A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l...
CVE-2026-5014MEDIUM5.5A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log...
CVE-2026-5013MEDIUM5.5A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key...
CVE-2026-5012HIGH7.3A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing ...
CVE-2026-5011MEDIUM6.3A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the fil...
CVE-2026-5007MEDIUM5.3A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file ...
CVE-2026-3256CRITICAL9.8HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now