2026 CVE Vulnerabilities

61,676 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44631CRITICAL9.8Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a...
CVE-2026-44186HIGH7.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server w...
CVE-2026-44185HIGH7.3Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T...
CVE-2026-44119MEDIUM5.5Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to r...
CVE-2026-43951MEDIUM6.5Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. T...
CVE-2026-42863HIGH8.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ...
CVE-2026-42862MEDIUM5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ...
CVE-2026-42861CRITICAL9.6Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ...
CVE-2026-42536HIGH7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content ...
CVE-2026-42535CRITICAL9.1A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate t...
CVE-2026-36786HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 paramete...
CVE-2026-34356HIGH7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie...
CVE-2026-34355HIGH7.5A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. U...
CVE-2026-34194HIGH7.1Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a ma...
CVE-2026-29170MEDIUM6.1A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4....
CVE-2026-29167CRITICAL9.8Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac...
CVE-2026-22164HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory....
CVE-2026-11529MEDIUM6.3A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read...
CVE-2026-11528HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/...
CVE-2026-11524HIGH8.8A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /gofo...
CVE-2026-11523HIGH8.8A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/Portal...
CVE-2026-11522HIGH8.8A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the f...
CVE-2026-49235HIGH7.5When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.
CVE-2026-49234HIGH7.5When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Rout...
CVE-2026-49233HIGH7.5Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths fo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now