2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48687CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integrat...
CVE-2026-48686CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachab...
CVE-2026-48685MEDIUM6.5FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib...
CVE-2026-48684MEDIUM6.5FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In ...
CVE-2026-48683MEDIUM6.5FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset p...
CVE-2026-46620MEDIUM6.5e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on c...
CVE-2026-43936MEDIUM4.3e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of...
CVE-2026-43935HIGH8.1e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p...
CVE-2026-43934MEDIUM6.5e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati...
CVE-2026-40564MEDIUM6.5Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku...
CVE-2026-38587MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex...
CVE-2026-25112HIGH7.8A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
CVE-2026-9552HIGH7.3A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown c...
CVE-2026-9551HIGH7.3A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ...
CVE-2026-9550HIGH7.3A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0....
CVE-2026-4480CRITICAL9A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma...
CVE-2026-46368HIGH8.8luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu...
CVE-2026-45247CRITICAL9.8Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that ...
CVE-2026-45082HIGH7.6Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability...
CVE-2026-43919——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a ...
CVE-2026-42785HIGH8.6OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra...
CVE-2026-42425HIGH8.6OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe...
CVE-2026-42347——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a ...
CVE-2026-41917MEDIUM6.9OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin...
CVE-2026-41401HIGH7.1libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now