2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12268HIGH8.8ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT recor...
CVE-2026-12267HIGH7.2ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy ...
CVE-2026-101040MEDIUM6.5A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affec...
CVE-2026-101039CRITICAL10A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element ...
CVE-2026-101038CRITICAL9.9A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAt...
CVE-2026-90979——LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the ...
CVE-2026-7172MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: pa...
CVE-2026-7171MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: pa...
CVE-2026-7170MEDIUM4.8Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: pa...
CVE-2026-101037CRITICAL9.9A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the...
CVE-2026-101036MEDIUM5.3A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.joi...
CVE-2026-101035MEDIUM5.3A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library sr...
CVE-2026-101018MEDIUM4.7A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the fi...
CVE-2026-95104HIGH7.5Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may...
CVE-2026-94287MEDIUM5.5A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attacke...
CVE-2026-94286HIGH7.1An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to c...
CVE-2026-94285MEDIUM5.1An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X serv...
CVE-2026-94284MEDIUM5.5An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be use...
CVE-2026-94283MEDIUM6.5An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be u...
CVE-2026-94282MEDIUM5.6An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by maliciou...
CVE-2026-86530HIGH7.2BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrat...
CVE-2026-86507MEDIUM6.1Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-a...
CVE-2026-85134HIGH8.8Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document a...
CVE-2026-82969MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution So...
CVE-2026-82915MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now