2026 CVE Vulnerabilities

56,373 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23833HIGH7.5ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2...
CVE-2026-23732HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbDa...
CVE-2026-1169HIGH8.8A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. ...
CVE-2026-22850HIGH8.3Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL...
CVE-2026-22037HIGH8.4The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr...
CVE-2026-22031HIGH8.8@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @f...
CVE-2026-1158HIGH8.8A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function set...
CVE-2026-1007HIGH7.6Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny...
CVE-2026-1157HIGH8.8A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the ...
CVE-2026-1156HIGH8.8A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBa...
CVE-2026-1155HIGH8.8A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiF...
CVE-2026-1150HIGH8.8A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg o...
CVE-2026-1149HIGH8.8A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg ...
CVE-2026-1145HIGH8.8A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_...
CVE-2026-1144HIGH8.8A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c o...
CVE-2026-1143HIGH8.8A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg o...
CVE-2026-1141HIGH8.8A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /a...
CVE-2026-1140HIGH8.8A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/Config...
CVE-2026-1139HIGH8.8A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /...
CVE-2026-1138HIGH8.8A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. ...
CVE-2026-1137HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof...
CVE-2026-0943HIGH7.5HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability...
CVE-2026-23644HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925...
CVE-2026-23525HIGH8.41Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulne...
CVE-2026-1112HIGH8.1A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now