2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-86167CRITICAL9.9A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin...
CVE-2026-86165CRITICAL9.8A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/...
CVE-2026-86218CRITICAL9.8N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVE-2026-75816CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all ...
CVE-2026-16310CRITICAL9.8The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
CVE-2026-86153CRITICAL9.1A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of th...
CVE-2026-86152CRITICAL10A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the fil...
CVE-2026-86151CRITICAL9.1A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/...
CVE-2026-86149CRITICAL9.1A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetC...
CVE-2026-86148CRITICAL9.1A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the f...
CVE-2026-86060CRITICAL9.8RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited chara...
CVE-2026-67278CRITICAL9.1MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificat...
CVE-2026-86190CRITICAL9.1WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user record...
CVE-2026-86189CRITICAL9.8WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to w...
CVE-2026-86184CRITICAL9.8Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows un...
CVE-2026-10196CRITICAL9.8The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-86124CRITICAL9.8AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces...
CVE-2026-86121CRITICAL9.8Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and...
CVE-2026-78362CRITICAL9.8The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its AP...
CVE-2026-83627CRITICAL9.8The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code ...
CVE-2026-13447CRITICAL9.8The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and includ...
CVE-2026-52777CRITICAL9.4YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerab...
CVE-2026-52766CRITICAL9.1YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseS...
CVE-2026-75925CRITICAL9.6Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands...
CVE-2026-50894CRITICAL9.8easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interfa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now