2026 CVE Vulnerabilities

53,154 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5465HIGH8.8The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object R...
CVE-2026-1839HIGH7.8A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code ...
CVE-2026-20433HIGH8.8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of...
CVE-2026-20432HIGH8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of...
CVE-2026-5692HIGH7.3A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the fil...
CVE-2026-5691HIGH7.3A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of th...
CVE-2026-5690HIGH7.3A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the...
CVE-2026-5689HIGH7.3A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of...
CVE-2026-5688HIGH7.3A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg...
CVE-2026-5709HIGH8.8Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01...
CVE-2026-5708HIGH8.8Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Stud...
CVE-2026-5707HIGH8.8Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (...
CVE-2026-5687HIGH8.8A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the f...
CVE-2026-5686HIGH8.8A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic ...
CVE-2026-5685HIGH8.8A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/...
CVE-2026-5684HIGH8A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilt...
CVE-2026-35442HIGH8.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (...
CVE-2026-35412HIGH8.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumab...
CVE-2026-35409HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request...
CVE-2026-5683HIGH8A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter o...
CVE-2026-35395HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistencia...
CVE-2026-35394HIGH8.8Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-...
CVE-2026-35391HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in...
CVE-2026-35389HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification...
CVE-2026-35213HIGH7.5@hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Reg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now