2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-69088HIGH8.6Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint...
CVE-2026-69087HIGH7.1The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th...
CVE-2026-69086HIGH8.3SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,...
CVE-2026-67608HIGH8.6Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti...
CVE-2026-18642HIGH7.8Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock ...
CVE-2026-18600HIGH8.8A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s...
CVE-2026-18092HIGH8.1Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm...
CVE-2026-18089HIGH7.5Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em...
CVE-2026-18599HIGH8A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f...
CVE-2026-18598HIGH8.8A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l...
CVE-2026-69082HIGH8.8CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th...
CVE-2026-69079HIGH8.7CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endp...
CVE-2026-69078HIGH8.8CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio...
CVE-2026-0392HIGH7.3eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is ...
CVE-2026-21555HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21554HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21553HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21552HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21551HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21550HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21549HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21548HIGH7.5In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec...
CVE-2026-9593HIGH8.4A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the ...
CVE-2026-4793HIGH7.3An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr...
CVE-2026-18587HIGH7.5A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now