2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5354 | HIGH | 8.8 | 4.8% | Apr 2, 2026 | A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the f... |
| CVE-2026-5353 | HIGH | 8.8 | 4.8% | Apr 2, 2026 | A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. P... |
| CVE-2026-5352 | HIGH | 8.8 | 4.1% | Apr 2, 2026 | A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /se... |
| CVE-2026-35386 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r... |
| CVE-2026-35385 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e... |
| CVE-2026-34830 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path ... |
| CVE-2026-34829 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only w... |
| CVE-2026-34826 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges pa... |
| CVE-2026-34785 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe... |
| CVE-2026-34230 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encodi... |
| CVE-2026-33951 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal... |
| CVE-2026-5351 | HIGH | 8.8 | 4.5% | Apr 2, 2026 | A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setu... |
| CVE-2026-5350 | HIGH | 8.8 | 0.8% | Apr 2, 2026 | A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of t... |
| CVE-2026-5349 | HIGH | 8.8 | 0.8% | Apr 2, 2026 | A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file... |
| CVE-2026-34876 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in lib... |
| CVE-2026-33691 | HIGH | 7.5 | 3.6% | Apr 2, 2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal... |
| CVE-2026-30332 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows... |
| CVE-2026-5346 | HIGH | 7.3 | 0.3% | Apr 2, 2026 | A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src... |
| CVE-2026-5339 | HIGH | 8.8 | 5.7% | Apr 2, 2026 | A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the ... |
| CVE-2026-34797 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34796 | HIGH | 8.8 | 1.5% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34795 | HIGH | 8.8 | 1.5% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34794 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34793 | HIGH | 8.8 | 1.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34792 | HIGH | 8.8 | 1.3% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now