2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32116HIGH8.1Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ...
CVE-2026-28254HIGH7.5A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate...
CVE-2026-28253HIGH7.5A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a...
CVE-2026-26794HIGH8.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v...
CVE-2026-28793HIGH8.4Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints...
CVE-2026-28791HIGH7.4Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel...
CVE-2026-28356HIGH7.5multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header...
CVE-2026-27940HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ...
CVE-2026-25529HIGH8.1Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un...
CVE-2026-21887HIGH7.7OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, th...
CVE-2026-21672HIGH8.8A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
CVE-2026-4043HIGH8.8A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDg...
CVE-2026-4042HIGH8.8A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of ...
CVE-2026-4041HIGH8.8A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/...
CVE-2026-21667HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21666HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-3099HIGH7.3A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does...
CVE-2026-4039HIGH8.8A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr...
CVE-2026-3989HIGH7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at...
CVE-2026-4008HIGH8.8A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSID...
CVE-2026-4007HIGH8.8A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifi...
CVE-2026-3978HIGH8.8A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/for...
CVE-2026-3976HIGH8.8A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /gof...
CVE-2026-3975HIGH8.8A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of t...
CVE-2026-3974HIGH8.8A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now