2026 CVE Vulnerabilities
53,154 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5465 | HIGH | 8.8 | 0.6% | Apr 7, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object R... |
| CVE-2026-1839 | HIGH | 7.8 | 0.3% | Apr 7, 2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code ... |
| CVE-2026-20433 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of... |
| CVE-2026-20432 | HIGH | 8 | 0.3% | Apr 7, 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of... |
| CVE-2026-5692 | HIGH | 7.3 | 1.4% | Apr 7, 2026 | A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the fil... |
| CVE-2026-5691 | HIGH | 7.3 | 1.2% | Apr 6, 2026 | A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of th... |
| CVE-2026-5690 | HIGH | 7.3 | 1.5% | Apr 6, 2026 | A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the... |
| CVE-2026-5689 | HIGH | 7.3 | 1.5% | Apr 6, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of... |
| CVE-2026-5688 | HIGH | 7.3 | 1.4% | Apr 6, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg... |
| CVE-2026-5709 | HIGH | 8.8 | 1.1% | Apr 6, 2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01... |
| CVE-2026-5708 | HIGH | 8.8 | 0.8% | Apr 6, 2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud... |
| CVE-2026-5707 | HIGH | 8.8 | 1.0% | Apr 6, 2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (... |
| CVE-2026-5687 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the f... |
| CVE-2026-5686 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic ... |
| CVE-2026-5685 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/... |
| CVE-2026-5684 | HIGH | 8 | 0.6% | Apr 6, 2026 | A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilt... |
| CVE-2026-35442 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (... |
| CVE-2026-35412 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumab... |
| CVE-2026-35409 | HIGH | 7.7 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request... |
| CVE-2026-5683 | HIGH | 8 | 0.6% | Apr 6, 2026 | A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter o... |
| CVE-2026-35395 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistencia... |
| CVE-2026-35394 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-... |
| CVE-2026-35391 | HIGH | 7.5 | 0.1% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in... |
| CVE-2026-35389 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification... |
| CVE-2026-35213 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | @hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Reg... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now