2026 CVE Vulnerabilities

48,542 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12218HIGH8A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformatio...
CVE-2026-12217HIGH7.8A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the libra...
CVE-2026-12214HIGH7.8A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBi...
CVE-2026-12204HIGH7.3A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/Pa...
CVE-2026-12200HIGH7.3A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown functi...
CVE-2026-12198HIGH7.3A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nos...
CVE-2026-12197HIGH7.3A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file ...
CVE-2026-12193HIGH7.8A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handle...
CVE-2026-12192HIGH8.8A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This ma...
CVE-2026-12191HIGH7.8A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the fi...
CVE-2026-12187HIGH8.8A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknow...
CVE-2026-12186HIGH8.8A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library...
CVE-2026-54413HIGH8.2driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_Se...
CVE-2026-54412HIGH8.2LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpac...
CVE-2026-54410HIGH8.6nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP serv...
CVE-2026-11527HIGH8.6Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of t...
CVE-2026-54420HIGH8.5LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide...
CVE-2026-12174HIGH8.8A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the f...
CVE-2026-6428HIGH7.6SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x b...
CVE-2026-5513HIGH7.2The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-9109HIGH7.2The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu...
CVE-2026-11769HIGH8.8We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t...
CVE-2026-9848HIGH7.5The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers...
CVE-2026-54230HIGH7.8A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr...
CVE-2026-54229HIGH7A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump direc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now