2026 CVE Vulnerabilities

70,445 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-26695CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CVE-2026-26694CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
CVE-2026-24115CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before co...
CVE-2026-24114CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflow...
CVE-2026-24113CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24111CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value...
CVE-2026-24109CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24108CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu...
CVE-2026-24107CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is d...
CVE-2026-23600CRITICAL9.8A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).
CVE-2026-0995LOW3.6An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to...
CVE-2026-26698MEDIUM4.9code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
CVE-2026-26697MEDIUM4.9code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?te...
CVE-2026-1628MEDIUM4.6Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma...
CVE-2026-3432CRITICAL9.1On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all author...
CVE-2026-3431CRITICAL9.8On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller ...
CVE-2026-2584CRITICAL9.3A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe...
CVE-2026-20445MEDIUM4.4In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic...
CVE-2026-20444MEDIUM6.7In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of ...
CVE-2026-20443MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2026-20442MEDIUM4.4In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali...
CVE-2026-20441MEDIUM6.7In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2026-20440MEDIUM6.7In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2026-20439MEDIUM4.4In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malic...
CVE-2026-20438MEDIUM6.4In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privileg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now