2026 CVE Vulnerabilities

53,211 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5354HIGH8.8A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the f...
CVE-2026-5353HIGH8.8A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. P...
CVE-2026-5352HIGH8.8A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /se...
CVE-2026-35386HIGH8.1In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r...
CVE-2026-35385HIGH8.1In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e...
CVE-2026-34830HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path ...
CVE-2026-34829HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only w...
CVE-2026-34826HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges pa...
CVE-2026-34785HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe...
CVE-2026-34230HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encodi...
CVE-2026-33951HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal...
CVE-2026-5351HIGH8.8A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setu...
CVE-2026-5350HIGH8.8A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of t...
CVE-2026-5349HIGH8.8A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file...
CVE-2026-34876HIGH7.5An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in lib...
CVE-2026-33691HIGH7.5The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal...
CVE-2026-30332HIGH7.5A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows...
CVE-2026-5346HIGH7.3A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src...
CVE-2026-5339HIGH8.8A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the ...
CVE-2026-34797HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34796HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34795HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34794HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34793HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34792HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now