2026 CVE Vulnerabilities

56,866 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22196HIGH8.1GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled...
CVE-2026-22195HIGH8.1GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled ...
CVE-2026-22194HIGH8.8GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the applicat...
CVE-2026-0803HIGH8.8A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the...
CVE-2026-22082HIGH8.8This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the u...
CVE-2026-22081HIGH8.8This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the m...
CVE-2026-22080HIGH8.7This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the t...
CVE-2026-22079HIGH8.7This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the p...
CVE-2026-21409HIGH8.2Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is condu...
CVE-2026-20976HIGH7.8Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
CVE-2026-20971HIGH7.8Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary c...
CVE-2026-20970HIGH7.8Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged AP...
CVE-2026-0733HIGH8.8A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown functi...
CVE-2026-0731HIGH7.5A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cst...
CVE-2026-0729HIGH7.2A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function o...
CVE-2026-0728HIGH7.2A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects ...
CVE-2026-22257HIGH8.8Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder...
CVE-2026-22256HIGH8.8Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder...
CVE-2026-22235HIGH8.7OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate thro...
CVE-2026-22230HIGH7.6OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access fu...
CVE-2026-22521HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-21639HIGH8.8A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol ...
CVE-2026-21638HIGH8.8A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol ...
CVE-2026-22255HIGH8.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio...
CVE-2026-22245HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now