2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6500MEDIUM4.8Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ...
CVE-2026-33523MEDIUM6.5HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve...
CVE-2026-33007MEDIUM5.3A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r...
CVE-2026-33006MEDIUM4.8A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot...
CVE-2026-29169HIGH7.5A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the s...
CVE-2026-23918HIGH8.8Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HT...
CVE-2026-6499LOW2.4Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina...
CVE-2026-6266HIGH8.3A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external...
CVE-2026-4928——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-34032MEDIUM5.3Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve...
CVE-2026-33857MEDIUM5.3Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: throu...
CVE-2026-31205MEDIUM5.7Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via t...
CVE-2026-7482CRITICAL9.1Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint...
CVE-2026-34059HIGH7.5Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are...
CVE-2026-24072HIGH8.8An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to re...
CVE-2026-3120HIGH7.2Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and...
CVE-2026-7750HIGH8.8A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRul...
CVE-2026-7749HIGH8.8A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of...
CVE-2026-7748HIGH8.8A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW o...
CVE-2026-33846HIGH7.5A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises ...
CVE-2026-7747CRITICAL9.8A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function l...
CVE-2026-7746MEDIUM6.3A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknow...
CVE-2026-7745MEDIUM6.3A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineCl...
CVE-2026-7744MEDIUM6.3A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassro...
CVE-2026-7743MEDIUM6.3A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now