2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-94194MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow...
CVE-2026-92103MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ...
CVE-2026-91043HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ...
CVE-2026-87752MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Informati...
CVE-2026-78424HIGH8.8Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write)...
CVE-2026-19444MEDIUM6.5A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When cop...
CVE-2026-12264HIGH8.8Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config syn...
CVE-2026-101054MEDIUM5.3A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_...
CVE-2026-101053HIGH7.3A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa...
CVE-2026-101052HIGH7.3A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of ...
CVE-2026-91006——Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JV...
CVE-2026-81867CRITICAL9.4A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration version...
CVE-2026-81375HIGH8.3A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 202...
CVE-2026-19759CRITICAL9.4An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prio...
CVE-2026-12269HIGH8.8Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the H...
CVE-2026-12268HIGH8.8ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT recor...
CVE-2026-12267HIGH7.2ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy ...
CVE-2026-101040MEDIUM6.5A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affec...
CVE-2026-101039CRITICAL10A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element ...
CVE-2026-101038CRITICAL9.9A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAt...
CVE-2026-90979——LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the ...
CVE-2026-7172MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: pa...
CVE-2026-7171MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: pa...
CVE-2026-7170MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: pa...
CVE-2026-101037CRITICAL9.9A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now