2026 CVE Vulnerabilities

56,336 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1498HIGH7An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensit...
CVE-2026-22623HIGH7.2Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can...
CVE-2026-0709HIGH7.2Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input valida...
CVE-2026-1699HIGH8.8In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar...
CVE-2026-22277HIGH7.8Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command...
CVE-2026-21418HIGH7.8Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ...
CVE-2026-25210HIGH7.8In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no...
CVE-2026-1680HIGH7.8Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Win...
CVE-2026-0963HIGH8.8An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote...
CVE-2026-0805HIGH8.8An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authen...
CVE-2026-24714HIGH8.7Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telne...
CVE-2026-1638HIGH8.8A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZ...
CVE-2026-1637HIGH8.8A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of th...
CVE-2026-25126HIGH7.1PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/...
CVE-2026-25117HIGH8.3pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6...
CVE-2026-25116HIGH8.8Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated ...
CVE-2026-25063HIGH7.8gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gr...
CVE-2026-25061HIGH7.5tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame ...
CVE-2026-25047HIGH8.8deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution ...
CVE-2026-25040HIGH8.8Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin...
CVE-2026-24905HIGH7.8Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-24902HIGH7.1TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass...
CVE-2026-1625HIGH8.8A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boa...
CVE-2026-1624HIGH8.8A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the...
CVE-2026-1610HIGH8.1A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now