2026 CVE Vulnerabilities
61,676 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44631 | CRITICAL | 9.8 | 0.5% | Jun 8, 2026 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a... |
| CVE-2026-44186 | HIGH | 7.3 | 0.6% | Jun 8, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server w... |
| CVE-2026-44185 | HIGH | 7.3 | 0.7% | Jun 8, 2026 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T... |
| CVE-2026-44119 | MEDIUM | 5.5 | 0.2% | Jun 8, 2026 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to r... |
| CVE-2026-43951 | MEDIUM | 6.5 | 0.5% | Jun 8, 2026 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. T... |
| CVE-2026-42863 | HIGH | 8.1 | 0.3% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ... |
| CVE-2026-42862 | MEDIUM | 5 | 0.2% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ... |
| CVE-2026-42861 | CRITICAL | 9.6 | 0.3% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ... |
| CVE-2026-42536 | HIGH | 7.5 | 1.0% | Jun 8, 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content ... |
| CVE-2026-42535 | CRITICAL | 9.1 | 0.5% | Jun 8, 2026 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate t... |
| CVE-2026-36786 | HIGH | 7.5 | 0.4% | Jun 8, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 paramete... |
| CVE-2026-34356 | HIGH | 7.5 | 0.7% | Jun 8, 2026 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie... |
| CVE-2026-34355 | HIGH | 7.5 | 1.2% | Jun 8, 2026 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. U... |
| CVE-2026-34194 | HIGH | 7.1 | 0.1% | Jun 8, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a ma... |
| CVE-2026-29170 | MEDIUM | 6.1 | 0.5% | Jun 8, 2026 | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.... |
| CVE-2026-29167 | CRITICAL | 9.8 | 0.7% | Jun 8, 2026 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac... |
| CVE-2026-22164 | HIGH | 7.5 | 0.3% | Jun 8, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.... |
| CVE-2026-11529 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read... |
| CVE-2026-11528 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/... |
| CVE-2026-11524 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /gofo... |
| CVE-2026-11523 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/Portal... |
| CVE-2026-11522 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the f... |
| CVE-2026-49235 | HIGH | 7.5 | 0.4% | Jun 8, 2026 | When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. |
| CVE-2026-49234 | HIGH | 7.5 | 0.3% | Jun 8, 2026 | When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Rout... |
| CVE-2026-49233 | HIGH | 7.5 | 0.4% | Jun 8, 2026 | Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths fo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now