2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-36616MEDIUM5.9Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s...
CVE-2026-36615MEDIUM4.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns...
CVE-2026-36613MEDIUM4.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents whe...
CVE-2026-36612MEDIUM6.4Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon...
CVE-2026-36611HIGH7.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST r...
CVE-2026-36610MEDIUM5.9Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64...
CVE-2026-36609HIGH7.3Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change ...
CVE-2026-36608HIGH8.8Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to ...
CVE-2026-36607HIGH8.8Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ...
CVE-2026-36606HIGH7.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ...
CVE-2026-36605MEDIUM6.5Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low numb...
CVE-2026-36604MEDIUM6.5Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS reb...
CVE-2026-36603HIGH8.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication...
CVE-2026-36602MEDIUM4.3Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInf...
CVE-2026-36460MEDIUM4.8Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save ...
CVE-2026-20233MEDIUM6.1A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote at...
CVE-2026-20230HIGH8.6A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...
CVE-2026-20175MEDIUM6.1A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote loc...
CVE-2026-6657HIGH8.8A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe...
CVE-2026-44281HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-42321HIGH8.4GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech...
CVE-2026-42320MEDIUM5.9GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0...
CVE-2026-42318HIGH7GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11....
CVE-2026-42317HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-3276MEDIUM6.3unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now