2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15952 | MEDIUM | 6.4 | — | Sep 28, 2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). ... |
| CVE-2026-101072 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.c... |
| CVE-2026-101071 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown cod... |
| CVE-2026-101070 | MEDIUM | 5.3 | — | Sep 28, 2026 | A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files o... |
| CVE-2026-86330 | HIGH | 7.2 | — | Sep 28, 2026 | An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This comp... |
| CVE-2026-82936 | MEDIUM | 5.9 | — | Sep 28, 2026 | mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express ... |
| CVE-2026-82935 | MEDIUM | 6.9 | — | Sep 28, 2026 | mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its produc... |
| CVE-2026-82933 | MEDIUM | 6 | — | Sep 28, 2026 | mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication ... |
| CVE-2026-82932 | MEDIUM | 5.3 | — | Sep 28, 2026 | mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, includin... |
| CVE-2026-82930 | MEDIUM | 6.4 | — | Sep 28, 2026 | mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocke... |
| CVE-2026-82929 | MEDIUM | 6.3 | — | Sep 28, 2026 | mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation... |
| CVE-2026-82928 | HIGH | 7.7 | — | Sep 28, 2026 | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential... |
| CVE-2026-82326 | MEDIUM | 4.1 | — | Sep 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational... |
| CVE-2026-82323 | HIGH | 8.1 | — | Sep 28, 2026 | Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform a... |
| CVE-2026-59563 | MEDIUM | 4.6 | — | Sep 28, 2026 | Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target res... |
| CVE-2026-52749 | MEDIUM | 5.3 | — | Sep 28, 2026 | The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerabil... |
| CVE-2026-52748 | HIGH | 7.1 | — | Sep 28, 2026 | The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. Th... |
| CVE-2026-18825 | MEDIUM | 5.3 | — | Sep 28, 2026 | An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verifi... |
| CVE-2026-12265 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endp... |
| CVE-2026-101292 | HIGH | 8.2 | — | Sep 28, 2026 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getF... |
| CVE-2026-101069 | MEDIUM | 6.5 | — | Sep 28, 2026 | A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/s... |
| CVE-2026-101068 | MEDIUM | 6.5 | — | Sep 28, 2026 | A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packag... |
| CVE-2026-101067 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile... |
| CVE-2026-101066 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packag... |
| CVE-2026-101055 | MEDIUM | 5.3 | — | Sep 28, 2026 | A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now