2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52749 | MEDIUM | 5.3 | — | Sep 28, 2026 | The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerabil... |
| CVE-2026-52748 | HIGH | 7.1 | — | Sep 28, 2026 | The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. Th... |
| CVE-2026-18825 | MEDIUM | 5.3 | — | Sep 28, 2026 | An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verifi... |
| CVE-2026-12265 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endp... |
| CVE-2026-101292 | HIGH | 8.2 | 0.4% | Sep 28, 2026 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getF... |
| CVE-2026-101069 | MEDIUM | 6.5 | — | Sep 28, 2026 | A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/s... |
| CVE-2026-101068 | MEDIUM | 6.5 | — | Sep 28, 2026 | A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packag... |
| CVE-2026-101067 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile... |
| CVE-2026-101066 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packag... |
| CVE-2026-101055 | MEDIUM | 5.3 | — | Sep 28, 2026 | A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET... |
| CVE-2026-94194 | MEDIUM | 6.3 | — | Sep 28, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow... |
| CVE-2026-92103 | MEDIUM | 6.3 | — | Sep 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ... |
| CVE-2026-91043 | HIGH | 8.2 | — | Sep 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ... |
| CVE-2026-87752 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Informati... |
| CVE-2026-78424 | HIGH | 8.8 | — | Sep 28, 2026 | Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write)... |
| CVE-2026-19444 | MEDIUM | 6.5 | — | Sep 28, 2026 | A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When cop... |
| CVE-2026-12264 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config syn... |
| CVE-2026-101054 | MEDIUM | 5.3 | — | Sep 28, 2026 | A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_... |
| CVE-2026-101053 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa... |
| CVE-2026-101052 | HIGH | 7.3 | — | Sep 28, 2026 | A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of ... |
| CVE-2026-91006 | — | — | 0.4% | Sep 28, 2026 | Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JV... |
| CVE-2026-81867 | CRITICAL | 9.4 | — | Sep 28, 2026 | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration version... |
| CVE-2026-81375 | HIGH | 8.3 | — | Sep 28, 2026 | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 202... |
| CVE-2026-19759 | CRITICAL | 9.4 | — | Sep 28, 2026 | An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prio... |
| CVE-2026-12269 | HIGH | 8.8 | — | Sep 28, 2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the H... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now