2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94194 | MEDIUM | 6.3 | — | Sep 28, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow... |
| CVE-2026-92103 | MEDIUM | 6.3 | — | Sep 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ... |
| CVE-2026-91043 | HIGH | 8.2 | — | Sep 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ... |
| CVE-2026-87752 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Informati... |
| CVE-2026-78424 | HIGH | 8.8 | — | Sep 28, 2026 | Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write)... |
| CVE-2026-19444 | MEDIUM | 6.5 | — | Sep 28, 2026 | A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When cop... |
| CVE-2026-12264 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config syn... |
| CVE-2026-101054 | MEDIUM | 5.3 | — | Sep 28, 2026 | A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_... |
| CVE-2026-101053 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa... |
| CVE-2026-101052 | HIGH | 7.3 | — | Sep 28, 2026 | A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of ... |
| CVE-2026-91006 | — | — | 0.4% | Sep 28, 2026 | Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JV... |
| CVE-2026-81867 | CRITICAL | 9.4 | — | Sep 28, 2026 | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration version... |
| CVE-2026-81375 | HIGH | 8.3 | — | Sep 28, 2026 | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 202... |
| CVE-2026-19759 | CRITICAL | 9.4 | — | Sep 28, 2026 | An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prio... |
| CVE-2026-12269 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the H... |
| CVE-2026-12268 | HIGH | 8.8 | — | Sep 28, 2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT recor... |
| CVE-2026-12267 | HIGH | 7.2 | — | Sep 28, 2026 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy ... |
| CVE-2026-101040 | MEDIUM | 6.5 | — | Sep 28, 2026 | A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affec... |
| CVE-2026-101039 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element ... |
| CVE-2026-101038 | CRITICAL | 9.9 | — | Sep 28, 2026 | A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAt... |
| CVE-2026-90979 | — | — | 0.2% | Sep 28, 2026 | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the ... |
| CVE-2026-7172 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: pa... |
| CVE-2026-7171 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: pa... |
| CVE-2026-7170 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: pa... |
| CVE-2026-101037 | CRITICAL | 9.9 | — | Sep 28, 2026 | A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now