2026 CVE Vulnerabilities

70,492 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1442HIGH7.8Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a...
CVE-2026-3286MEDIUM4.3A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save ...
CVE-2026-2428HIGH7.5The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in...
CVE-2026-28364HIGH7.8In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re...
CVE-2026-28363HIGH8.8In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation...
CVE-2026-3285HIGH7.8A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the ...
CVE-2026-3284MEDIUM5.5A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conver...
CVE-2026-3283HIGH7.1A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file li...
CVE-2026-3282HIGH7.1A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file li...
CVE-2026-3281HIGH7.8A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conver...
CVE-2026-3275HIGH8.8A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre...
CVE-2026-3274HIGH8.8A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f...
CVE-2026-3037HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t...
CVE-2026-25721HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25196HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-25105HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta...
CVE-2026-25037HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-24498HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network...
CVE-2026-24497CRITICAL9.8Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue aff...
CVE-2026-24452HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker...
CVE-2026-23702HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-22877CRITICAL9.1An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to...
CVE-2026-20797CRITICAL9.8A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att...
CVE-2026-20764HIGH8.8An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ...
CVE-2026-3273HIGH8.8A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now