2026 CVE Vulnerabilities

70,424 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0689MEDIUM4.9In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an ...
CVE-2026-26703CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php...
CVE-2026-26702CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.
CVE-2026-26696CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
CVE-2026-26695CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CVE-2026-26694CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
CVE-2026-24115CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before co...
CVE-2026-24114CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflow...
CVE-2026-24113CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24111CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value...
CVE-2026-24109CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24108CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24107CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is d...
CVE-2026-23600CRITICAL9.8A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).
CVE-2026-0995LOW3.6An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to...
CVE-2026-26698MEDIUM4.9code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
CVE-2026-26697MEDIUM4.9code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?te...
CVE-2026-1628MEDIUM4.6Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma...
CVE-2026-3432CRITICAL9.1On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all author...
CVE-2026-3431CRITICAL9.8On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller ...
CVE-2026-2584CRITICAL9.3A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe...
CVE-2026-20445MEDIUM4.4In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic...
CVE-2026-20444MEDIUM6.7In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of ...
CVE-2026-20443MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2026-20442MEDIUM4.4In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now