2026 CVE Vulnerabilities

45,193 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-15557HIGH7.3A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna...
CVE-2026-15548HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub...
CVE-2026-62143HIGH8.3A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules....
CVE-2026-15574HIGH7.5A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat...
CVE-2026-15545HIGH8.8A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ...
CVE-2026-15544HIGH8.8A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcu...
CVE-2026-15543HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertList...
CVE-2026-15542HIGH7.3A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.g...
CVE-2026-15541HIGH7.3A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a...
CVE-2026-14165HIGH7.5An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through ...
CVE-2026-15537HIGH7.3A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown c...
CVE-2026-12582HIGH8.6The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-12275HIGH7.1The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enr...
CVE-2026-11963HIGH8.1The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membershi...
CVE-2026-9492HIGH8.5The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an ...
CVE-2026-7162HIGH7.8Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to ...
CVE-2026-15517HIGH7.3A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma...
CVE-2026-15515HIGH7A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown process...
CVE-2026-15514HIGH7.3A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCS...
CVE-2026-15506HIGH7.8A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func...
CVE-2026-10667HIGH7.8Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l...
CVE-2026-10665HIGH7.4In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou...
CVE-2026-58596HIGH8.3Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o...
CVE-2026-61875HIGH8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav...
CVE-2026-59260HIGH8.8OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now