2026 CVE Vulnerabilities

51,340 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7717HIGH8.8A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. This issue affects the function UploadCustomModul...
CVE-2026-42365HIGH7.5A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A ...
CVE-2026-42364HIGH8.8An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A s...
CVE-2026-7711HIGH7.3A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/h...
CVE-2026-7710HIGH7.3A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the...
CVE-2026-7703HIGH7.3A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the compon...
CVE-2026-7698HIGH7.3A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is ...
CVE-2026-7695HIGH7.3A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0....
CVE-2026-7694HIGH7.3A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impa...
CVE-2026-7685HIGH8.8A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN....
CVE-2026-7684HIGH8.8A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file ...
CVE-2026-5063HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-7679HIGH7.3A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the...
CVE-2026-7675HIGH8.8A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_l...
CVE-2026-7674HIGH8.8A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_sin...
CVE-2026-7670HIGH7.3A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma...
CVE-2026-7668HIGH7.3A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in ...
CVE-2026-7644HIGH7.3A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil...
CVE-2026-7632HIGH7.3A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function ...
CVE-2026-7630HIGH7.3A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallService...
CVE-2026-2554HIGH8.1The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2026-6320HIGH7.5The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and...
CVE-2026-4100HIGH7.1The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo...
CVE-2026-4062HIGH7.5The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_i...
CVE-2026-4061HIGH7.5The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now