2026 CVE Vulnerabilities

53,334 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3321HIGH8.7A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME...
CVE-2026-28527HIGH7.3BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY...
CVE-2026-5121HIGH7.5A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ...
CVE-2026-4416HIGH8.5The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate...
CVE-2026-3945HIGH8.7An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ...
CVE-2026-2328HIGH7.5An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i...
CVE-2026-5119HIGH8.2A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies ...
CVE-2026-5105HIGH8.8A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassC...
CVE-2026-5104HIGH8.8A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStatic...
CVE-2026-5103HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of ...
CVE-2026-3124HIGH7.5The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i...
CVE-2026-5102HIGH8.8A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function s...
CVE-2026-2370HIGH8.8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2026-5101HIGH8.8A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the fil...
CVE-2026-4946HIGH8.8Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data...
CVE-2026-0562HIGH8.3A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or rej...
CVE-2026-0560HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th...
CVE-2026-34005HIGH8.8In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via s...
CVE-2026-5046HIGH8.8A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExt...
CVE-2026-5045HIGH8.8A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/W...
CVE-2026-5044HIGH8.8A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of...
CVE-2026-33575HIGH8.6OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai...
CVE-2026-33573HIGH8.8OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authentica...
CVE-2026-32980HIGH8.7OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-sec...
CVE-2026-32978HIGH7.5OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now