2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52749MEDIUM5.3The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerabil...
CVE-2026-52748HIGH7.1The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. Th...
CVE-2026-18825MEDIUM5.3An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verifi...
CVE-2026-12265HIGH8.8Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endp...
CVE-2026-101292HIGH8.2Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getF...
CVE-2026-101069MEDIUM6.5A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/s...
CVE-2026-101068MEDIUM6.5A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packag...
CVE-2026-101067HIGH7.3A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile...
CVE-2026-101066HIGH7.3A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packag...
CVE-2026-101055MEDIUM5.3A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET...
CVE-2026-94194MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow...
CVE-2026-92103MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ...
CVE-2026-91043HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server ...
CVE-2026-87752MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Informati...
CVE-2026-78424HIGH8.8Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write)...
CVE-2026-19444MEDIUM6.5A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When cop...
CVE-2026-12264HIGH8.8Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config syn...
CVE-2026-101054MEDIUM5.3A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_...
CVE-2026-101053HIGH7.3A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa...
CVE-2026-101052HIGH7.3A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of ...
CVE-2026-91006——Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JV...
CVE-2026-81867CRITICAL9.4A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration version...
CVE-2026-81375HIGH8.3A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 202...
CVE-2026-19759CRITICAL9.4An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prio...
CVE-2026-12269HIGH8.8Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the H...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now