2026 CVE Vulnerabilities

55,159 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4039HIGH8.8A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr...
CVE-2026-3989HIGH7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at...
CVE-2026-4008HIGH8.8A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSID...
CVE-2026-4007HIGH8.8A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifi...
CVE-2026-3978HIGH8.8A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/for...
CVE-2026-3976HIGH8.8A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /gof...
CVE-2026-3975HIGH8.8A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of t...
CVE-2026-3974HIGH8.8A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the ...
CVE-2026-3657HIGH7.5The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action...
CVE-2026-3973HIGH8.8A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/...
CVE-2026-3972HIGH8.8A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /gofo...
CVE-2026-3971HIGH8.8A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset ...
CVE-2026-3970HIGH8.8A flaw has been found in Tenda i3 1.0.0.6(2204). Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget...
CVE-2026-3969HIGH7.3A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basi...
CVE-2026-3936HIGH8.8Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially ex...
CVE-2026-3932HIGH7.5Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to b...
CVE-2026-3931HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds ...
CVE-2026-3926HIGH8.8Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memo...
CVE-2026-3924HIGH7.5use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the...
CVE-2026-3923HIGH8.8Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap ...
CVE-2026-3922HIGH8.8Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h...
CVE-2026-3921HIGH8.8Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit ...
CVE-2026-3920HIGH8.8Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially ex...
CVE-2026-3919HIGH8.8Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install...
CVE-2026-3918HIGH8.8Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now