2026 CVE Vulnerabilities

61,676 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49232HIGH8.7Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such a...
CVE-2026-43974HIGH7.5Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server t...
CVE-2026-43973HIGH7.5Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust ...
CVE-2026-43972HIGH7.2Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unval...
CVE-2026-36789HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the f...
CVE-2026-25558MEDIUM4.8QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authent...
CVE-2026-11521MEDIUM6.3A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29a...
CVE-2026-11520LOW3.5A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional...
CVE-2026-11519MEDIUM6.3A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-11518MEDIUM4.3A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /user...
CVE-2026-11517HIGH8.8A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /gofo...
CVE-2026-11516MEDIUM5.5A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/fo...
CVE-2026-9549MEDIUM4.8Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and ...
CVE-2026-8833MEDIUM5.4Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0...
CVE-2026-8078MEDIUM4.8Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 v...
CVE-2026-7765MEDIUM5.3Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints ...
CVE-2026-7186MEDIUM5.4Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 version...
CVE-2026-11577Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to...
CVE-2026-11515MEDIUM5.5A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The ...
CVE-2026-11514MEDIUM6.3A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the...
CVE-2026-11513MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file...
CVE-2026-11512MEDIUM4.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unkno...
CVE-2026-11511LOW3.5A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/...
CVE-2026-50752HIGH7.4A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke...
CVE-2026-50751CRITICAL9.3A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now