2026 CVE Vulnerabilities

53,401 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33479HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json....
CVE-2026-31847HIGH8.8Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0...
CVE-2026-1958HIGH8.7Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several i...
CVE-2026-32969HIGH7.5An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s a...
CVE-2026-31846HIGH7.1Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 a...
CVE-2026-23555HIGH7.1Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstor...
CVE-2026-23554HIGH7.8The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, ...
CVE-2026-4602HIGH7.5Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand...
CVE-2026-4598HIGH7.5Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsb...
CVE-2026-4570HIGH8.8A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the ...
CVE-2026-4566HIGH8.8A flaw has been found in Belkin F9K1122 1.00.33. The affected element is the function formWISP5G of the file /goform/for...
CVE-2026-4565HIGH8.8A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetN...
CVE-2026-4562HIGH7.3A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/c...
CVE-2026-2580HIGH7.5The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2026-4558HIGH8.8A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartCo...
CVE-2026-4555HIGH8.8A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the f...
CVE-2026-4554HIGH8.8A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the f...
CVE-2026-33319HIGH7.5WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialM...
CVE-2026-33293HIGH8.1WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/clo...
CVE-2026-33292HIGH7.5WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vuln...
CVE-2026-4553HIGH8.8A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit...
CVE-2026-4552HIGH8.8A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform...
CVE-2026-4551HIGH8.8A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the fil...
CVE-2026-4546HIGH7.3A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextSha...
CVE-2026-4545HIGH7.3A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PR...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now