2026 CVE Vulnerabilities

51,530 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7470HIGH8.8A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /...
CVE-2026-7468HIGH7.3A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the...
CVE-2026-7446HIGH7.3A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_res...
CVE-2026-7443HIGH7.3A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function ...
CVE-2026-7420HIGH8.8A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of th...
CVE-2026-7419HIGH8.8A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of ...
CVE-2026-7418HIGH8.8A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function st...
CVE-2026-7417HIGH7.3A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/serv...
CVE-2026-7416HIGH7.3A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests ...
CVE-2026-7404HIGH7.3A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_p...
CVE-2026-7426HIGH8.1Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V...
CVE-2026-7400HIGH7.3A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is...
CVE-2026-34965HIGH8.8Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection en...
CVE-2026-7466HIGH8.8AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline file...
CVE-2026-7424HIGH8.1Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent netwo...
CVE-2026-7422HIGH7.1Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass ...
CVE-2026-7398HIGH7.3A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulne...
CVE-2026-28221HIGH8.2Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo...
CVE-2026-27105HIGH7.1Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link...
CVE-2026-5712HIGH8.8This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi...
CVE-2026-6914HIGH7.5Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD...
CVE-2026-0204HIGH8A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access...
CVE-2026-7389HIGH7.3A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of t...
CVE-2026-7386HIGH7.3A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp...
CVE-2026-6849HIGH8.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now