2026 CVE Vulnerabilities

70,478 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3385MEDIUM5.5A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wre...
CVE-2026-3384MEDIUM5.5A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_No...
CVE-2026-3383MEDIUM5.5A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the ...
CVE-2026-3382MEDIUM5.5A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Nu...
CVE-2026-3380HIGH8.8A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. T...
CVE-2026-3379HIGH8.8A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file ...
CVE-2026-3378HIGH8.8A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex...
CVE-2026-3377HIGH8.8A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file...
CVE-2026-3376HIGH8.8A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSaf...
CVE-2026-28562CRITICAL9.8wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause ...
CVE-2026-28561MEDIUM4.8wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent...
CVE-2026-28560MEDIUM4.8wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data...
CVE-2026-28559MEDIUM6.9wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve priva...
CVE-2026-28558MEDIUM5.4wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload...
CVE-2026-28557HIGH7.1wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp...
CVE-2026-28556MEDIUM5.4wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,...
CVE-2026-28555MEDIUM5.3wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo...
CVE-2026-28554MEDIUM5.3wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u...
CVE-2026-3010MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T...
CVE-2026-2844HIGH7.5Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani...
CVE-2026-2471HIGH7.5The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1...
CVE-2026-1542MEDIUM6.5The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated...
CVE-2026-2647——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-28517CRITICAL9.8openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.ph...
CVE-2026-28516HIGH8.8openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now