2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15952MEDIUM6.4Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). ...
CVE-2026-101072CRITICAL10A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.c...
CVE-2026-101071MEDIUM6.3A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown cod...
CVE-2026-101070MEDIUM5.3A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files o...
CVE-2026-86330HIGH7.2An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This comp...
CVE-2026-82936MEDIUM5.9mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express ...
CVE-2026-82935MEDIUM6.9mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its produc...
CVE-2026-82933MEDIUM6mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication ...
CVE-2026-82932MEDIUM5.3mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, includin...
CVE-2026-82930MEDIUM6.4mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocke...
CVE-2026-82929MEDIUM6.3mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation...
CVE-2026-82928HIGH7.7mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential...
CVE-2026-82326MEDIUM4.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational...
CVE-2026-82323HIGH8.1Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform a...
CVE-2026-59563MEDIUM4.6Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target res...
CVE-2026-52749MEDIUM5.3The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerabil...
CVE-2026-52748HIGH7.1The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. Th...
CVE-2026-18825MEDIUM5.3An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verifi...
CVE-2026-12265HIGH8.8Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endp...
CVE-2026-101292HIGH8.2Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getF...
CVE-2026-101069MEDIUM6.5A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/s...
CVE-2026-101068MEDIUM6.5A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packag...
CVE-2026-101067HIGH7.3A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile...
CVE-2026-101066HIGH7.3A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packag...
CVE-2026-101055MEDIUM5.3A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now