2026 CVE Vulnerabilities

69,041 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2376MEDIUM5.4A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ...
CVE-2026-26793CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. Thi...
CVE-2026-3841HIGH8.8A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5...
CVE-2026-32141HIGH7.5flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve...
CVE-2026-32140HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ...
CVE-2026-32139MEDIUM5.4Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload...
CVE-2026-32137HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasourc...
CVE-2026-32129HIGH8.7soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (...
CVE-2026-32116HIGH8.1Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ...
CVE-2026-32100MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul...
CVE-2026-31890MEDIUM5.5Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-31873MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin...
CVE-2026-31860MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ...
CVE-2026-28256CRITICAL9.8A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge coul...
CVE-2026-28255CRITICAL9.8A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attack...
CVE-2026-28254HIGH7.5A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate...
CVE-2026-28253HIGH7.5A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a...
CVE-2026-28252CRITICAL9.8A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge co...
CVE-2026-26795CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the ...
CVE-2026-26794HIGH8.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v...
CVE-2026-26792CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade func...
CVE-2026-26791CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in...
CVE-2026-4045LOW3.7A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php...
CVE-2026-31841MEDIUM6.5Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0...
CVE-2026-29066MEDIUM6.2Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now