2026 CVE Vulnerabilities

51,080 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8260HIGH8.8A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of th...
CVE-2026-8259HIGH7.2A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /go...
CVE-2026-8177HIGH7.5XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing trunc...
CVE-2026-45180HIGH7.5Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the sta...
CVE-2026-8234HIGH8.8A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWif...
CVE-2026-45186HIGH7.5In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via...
CVE-2026-7263HIGH7.5In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly,...
CVE-2026-8230HIGH8.8A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/lo...
CVE-2026-8229HIGH8.8A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-...
CVE-2026-8228HIGH8.8A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-...
CVE-2026-8227HIGH8.8A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin...
CVE-2026-8226HIGH7.5A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install...
CVE-2026-8225HIGH7.5A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete ...
CVE-2026-7568HIGH7.5In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f...
CVE-2026-7262HIGH7.5In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve...
CVE-2026-7258HIGH7.5In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i...
CVE-2026-8224HIGH7.5A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of...
CVE-2026-8223HIGH7.5A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_a...
CVE-2026-8222HIGH7.5A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function pcf_nbsf_management_handle_register of t...
CVE-2026-8216HIGH7.3A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function i...
CVE-2026-42606HIGH8.8AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middlewa...
CVE-2026-42605HIGH8.8AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request...
CVE-2026-42575HIGH7.5apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi...
CVE-2026-42574HIGH7.5apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before versi...
CVE-2026-42562HIGH8.3Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now