2026 CVE Vulnerabilities

56,318 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22227HIGH7.2A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora...
CVE-2026-22226HIGH7.2A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu...
CVE-2026-22225HIGH7.2A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the...
CVE-2026-22224HIGH7.2A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface...
CVE-2026-22223HIGH8An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack...
CVE-2026-22222HIGH8An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attack...
CVE-2026-22221HIGH8An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack...
CVE-2026-0631HIGH8An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjace...
CVE-2026-0630HIGH8An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent ...
CVE-2026-24071HIGH7.8It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting clie...
CVE-2026-24070HIGH8.8During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe...
CVE-2026-1761HIGH8.6A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP ...
CVE-2026-1186HIGH8.6EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (defa...
CVE-2026-0599HIGH7.5A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploi...
CVE-2026-1117HIGH8.2A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated a...
CVE-2026-20412HIGH7.8In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2026-20411HIGH7.8In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv...
CVE-2026-20409HIGH7.8In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2026-20408HIGH8.8In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja...
CVE-2026-20401HIGH7.5In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if...
CVE-2026-22888HIGH7.5Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of p...
CVE-2026-1746HIGH8.8A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap...
CVE-2026-1531HIGH8.1A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification...
CVE-2026-1530HIGH8.1A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) atta...
CVE-2026-25201HIGH8.8An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now