2026 CVE Vulnerabilities

55,151 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32231HIGH8.2ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields...
CVE-2026-32138HIGH8.2NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P...
CVE-2026-3841HIGH8.8A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5...
CVE-2026-32141HIGH7.5flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve...
CVE-2026-32140HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ...
CVE-2026-32137HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasourc...
CVE-2026-32129HIGH8.7soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (...
CVE-2026-32116HIGH8.1Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ...
CVE-2026-28254HIGH7.5A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate...
CVE-2026-28253HIGH7.5A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a...
CVE-2026-26794HIGH8.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v...
CVE-2026-28793HIGH8.4Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints...
CVE-2026-28791HIGH7.4Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel...
CVE-2026-28356HIGH7.5multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header...
CVE-2026-27940HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ...
CVE-2026-25529HIGH8.1Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un...
CVE-2026-21887HIGH7.7OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, th...
CVE-2026-21672HIGH8.8A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
CVE-2026-4043HIGH8.8A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDg...
CVE-2026-4042HIGH8.8A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of ...
CVE-2026-4041HIGH8.8A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/...
CVE-2026-21667HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21666HIGH8.8A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-3099HIGH7.3A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does...
CVE-2026-4039HIGH8.8A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now