2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36616 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s... |
| CVE-2026-36615 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns... |
| CVE-2026-36613 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents whe... |
| CVE-2026-36612 | MEDIUM | 6.4 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon... |
| CVE-2026-36611 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST r... |
| CVE-2026-36610 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64... |
| CVE-2026-36609 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change ... |
| CVE-2026-36608 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to ... |
| CVE-2026-36607 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ... |
| CVE-2026-36606 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ... |
| CVE-2026-36605 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low numb... |
| CVE-2026-36604 | MEDIUM | 6.5 | 0.3% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS reb... |
| CVE-2026-36603 | HIGH | 8.1 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication... |
| CVE-2026-36602 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInf... |
| CVE-2026-36460 | MEDIUM | 4.8 | 0.2% | Jun 3, 2026 | Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save ... |
| CVE-2026-20233 | MEDIUM | 6.1 | 0.2% | Jun 3, 2026 | A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote at... |
| CVE-2026-20230 | HIGH | 8.6 | 41.7% | Jun 3, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
| CVE-2026-20175 | MEDIUM | 6.1 | 0.2% | Jun 3, 2026 | A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote loc... |
| CVE-2026-6657 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe... |
| CVE-2026-44281 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-42321 | HIGH | 8.4 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech... |
| CVE-2026-42320 | MEDIUM | 5.9 | 0.2% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-42318 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.... |
| CVE-2026-42317 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-3276 | MEDIUM | 6.3 | 0.5% | Jun 3, 2026 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now