2026 CVE Vulnerabilities

68,768 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29516MEDIUM6.9Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability...
CVE-2026-28430CRITICAL9.8Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera...
CVE-2026-26304MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which ...
CVE-2026-32261HIGH8.5Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w...
CVE-2026-4269HIGH7.5A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a...
CVE-2026-4254CRITICAL9.8A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of th...
CVE-2026-4253HIGH7.2A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of th...
CVE-2026-4224HIGH7.5When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply ...
CVE-2026-3644HIGH7.5The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()...
CVE-2026-29521MEDIUM5.1Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows atta...
CVE-2026-29520MEDIUM6.1Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Netwo...
CVE-2026-29513MEDIUM5.4Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut...
CVE-2026-29510MEDIUM5.4Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut...
CVE-2026-28498HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulne...
CVE-2026-28490MEDIUM6.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic paddi...
CVE-2026-27962CRITICAL9.1Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injectio...
CVE-2026-23862HIGH7.8Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a C...
CVE-2026-23489CRITICAL9.1Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possi...
CVE-2026-4270MEDIUM6.8Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= ...
CVE-2026-4252CRITICAL9.8A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the com...
CVE-2026-4251LOW2.5A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknow...
CVE-2026-30405HIGH7.5An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
CVE-2026-4276HIGH7.5LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
CVE-2026-4250LOW2.5A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an un...
CVE-2026-32587MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now