2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33010HIGH8.8mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP ser...
CVE-2026-32710CRITICAL9.9MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 befo...
CVE-2026-32318MEDIUM5.9Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2....
CVE-2026-32317MEDIUM5.9Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio...
CVE-2026-32310MEDIUM5.3Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault confi...
CVE-2026-32309HIGH7.5Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow expli...
CVE-2026-4495LOW3.5A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/...
CVE-2026-4494LOW3.5A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/...
CVE-2026-4493HIGH8.8A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file...
CVE-2026-4492HIGH8.8A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file...
CVE-2026-32844MEDIUM6.1XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method....
CVE-2026-32303MEDIUM5.9Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit...
CVE-2026-31836HIGH8.1Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and...
CVE-2026-30580MEDIUM4.3File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" func...
CVE-2026-30579MEDIUM6.5File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" function...
CVE-2026-30578MEDIUM6.5File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of th...
CVE-2026-4491HIGH8.8A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /gofo...
CVE-2026-4490HIGH8.8A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/ope...
CVE-2026-29828MEDIUM6.1DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field proj...
CVE-2026-22902MEDIUM6.7A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac...
CVE-2026-22901CRITICAL9.8A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, th...
CVE-2026-22900CRITICAL9.8A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exp...
CVE-2026-22898CRITICAL9.8A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers c...
CVE-2026-22897CRITICAL9.8A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vul...
CVE-2026-22895MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an admi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now