2026 CVE Vulnerabilities

56,124 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26732HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPas...
CVE-2026-26731HIGH8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`param...
CVE-2026-24734HIGH7.5Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na...
CVE-2026-2618HIGH7.4A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se...
CVE-2026-23648HIGH8.5Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss...
CVE-2026-2617HIGH8.8A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Serv...
CVE-2026-25087HIGH7Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It ca...
CVE-2026-2615HIGH7.3A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete...
CVE-2026-2247HIGH8.3SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a prev...
CVE-2026-1216HIGH7.2The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in ...
CVE-2026-2592HIGH7.7The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd...
CVE-2026-2474HIGH7.5Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_...
CVE-2026-2001HIGH8.8The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check ...
CVE-2026-2567HIGH7.3A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the f...
CVE-2026-2566HIGH7.3A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of ...
CVE-2026-2101HIGH8.7A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 ...
CVE-2026-26930HIGH7.2SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
CVE-2026-2563HIGH8.8A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen...
CVE-2026-2562HIGH8.8A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen ...
CVE-2026-2561HIGH8.8A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_upti...
CVE-2026-2447HIGH8.8Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32...
CVE-2026-1335HIGH7.8An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLI...
CVE-2026-1334HIGH7.8An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLID...
CVE-2026-1333HIGH7.8A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Rel...
CVE-2026-2555HIGH7.5A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now