2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4489HIGH8.8A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wif...
CVE-2026-4488HIGH8.8A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the fil...
CVE-2026-32989HIGH8.8Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authent...
CVE-2026-32986MEDIUM6.1Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject...
CVE-2026-4519LOW3.3The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer...
CVE-2026-4487HIGH8.8A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /gof...
CVE-2026-33312MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, t...
CVE-2026-29794MEDIUM5.3Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau...
CVE-2026-22172CRITICAL9.9OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that al...
CVE-2026-4486HIGH8.8A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/form...
CVE-2026-4485MEDIUM6.3A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio...
CVE-2026-33372MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability e...
CVE-2026-33371MEDIUM4.3An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i...
CVE-2026-33370MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-33369MEDIUM4.3Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a F...
CVE-2026-33368MEDIUM6.1Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Clas...
CVE-2026-31382MEDIUM6.1The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s...
CVE-2026-31381MEDIUM5.3An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb...
CVE-2026-4434HIGH8.1Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-...
CVE-2026-33136MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33135MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33134HIGH8.8WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vuln...
CVE-2026-33133HIGH7.2WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL...
CVE-2026-33132MEDIUM5.3ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t...
CVE-2026-33131CRITICAL9.1H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now