2026 CVE Vulnerabilities
70,478 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3385 | MEDIUM | 5.5 | 0.2% | Mar 1, 2026 | A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wre... |
| CVE-2026-3384 | MEDIUM | 5.5 | 0.2% | Mar 1, 2026 | A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_No... |
| CVE-2026-3383 | MEDIUM | 5.5 | 0.2% | Mar 1, 2026 | A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the ... |
| CVE-2026-3382 | MEDIUM | 5.5 | 0.2% | Mar 1, 2026 | A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Nu... |
| CVE-2026-3380 | HIGH | 8.8 | 0.8% | Mar 1, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. T... |
| CVE-2026-3379 | HIGH | 8.8 | 0.7% | Mar 1, 2026 | A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file ... |
| CVE-2026-3378 | HIGH | 8.8 | 0.7% | Mar 1, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex... |
| CVE-2026-3377 | HIGH | 8.8 | 0.7% | Mar 1, 2026 | A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file... |
| CVE-2026-3376 | HIGH | 8.8 | 0.7% | Feb 28, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSaf... |
| CVE-2026-28562 | CRITICAL | 9.8 | 0.4% | Feb 28, 2026 | wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause ... |
| CVE-2026-28561 | MEDIUM | 4.8 | 0.2% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent... |
| CVE-2026-28560 | MEDIUM | 4.8 | 0.2% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data... |
| CVE-2026-28559 | MEDIUM | 6.9 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve priva... |
| CVE-2026-28558 | MEDIUM | 5.4 | 0.2% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload... |
| CVE-2026-28557 | HIGH | 7.1 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp... |
| CVE-2026-28556 | MEDIUM | 5.4 | 0.2% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,... |
| CVE-2026-28555 | MEDIUM | 5.3 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo... |
| CVE-2026-28554 | MEDIUM | 5.3 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u... |
| CVE-2026-3010 | MEDIUM | 6.1 | 0.2% | Feb 28, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2026-2844 | HIGH | 7.5 | 0.3% | Feb 28, 2026 | Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani... |
| CVE-2026-2471 | HIGH | 7.5 | 0.4% | Feb 28, 2026 | The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1... |
| CVE-2026-1542 | MEDIUM | 6.5 | 0.2% | Feb 28, 2026 | The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated... |
| CVE-2026-2647 | — | — | — | Feb 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-28517 | CRITICAL | 9.8 | 5.6% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.ph... |
| CVE-2026-28516 | HIGH | 8.8 | 1.0% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now