2026 CVE Vulnerabilities

55,807 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3378HIGH8.8A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex...
CVE-2026-3377HIGH8.8A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file...
CVE-2026-3376HIGH8.8A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSaf...
CVE-2026-28557HIGH7.1wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp...
CVE-2026-2844HIGH7.5Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani...
CVE-2026-2471HIGH7.5The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1...
CVE-2026-28516HIGH8.8openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The ...
CVE-2026-28515HIGH8.8openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and conta...
CVE-2026-28425HIGH8Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenti...
CVE-2026-28423HIGH8.6Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide ...
CVE-2026-28421HIGH7.8Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati...
CVE-2026-28417HIGH7.8Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists...
CVE-2026-28416HIGH8.6Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo...
CVE-2026-28414HIGH7.5Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win...
CVE-2026-28409HIGH7.2WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne...
CVE-2026-28406HIGH8.2kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers...
CVE-2026-28402HIGH7.1nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-28400HIGH7.5Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e...
CVE-2026-27939HIGH8.8Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6...
CVE-2026-28270HIGH7.2Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl...
CVE-2026-27947HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an...
CVE-2026-27836HIGH7.5phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p...
CVE-2026-27832HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, an...
CVE-2026-27757HIGH7.2SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic...
CVE-2026-27752HIGH8.2SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now