2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12268 | HIGH | 8.8 | — | Sep 28, 2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT recor... |
| CVE-2026-12267 | HIGH | 7.2 | — | Sep 28, 2026 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy ... |
| CVE-2026-101040 | MEDIUM | 6.5 | — | Sep 28, 2026 | A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affec... |
| CVE-2026-101039 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element ... |
| CVE-2026-101038 | CRITICAL | 9.9 | — | Sep 28, 2026 | A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAt... |
| CVE-2026-90979 | — | — | 0.2% | Sep 28, 2026 | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the ... |
| CVE-2026-7172 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: pa... |
| CVE-2026-7171 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: pa... |
| CVE-2026-7170 | MEDIUM | 4.8 | — | Sep 28, 2026 | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: pa... |
| CVE-2026-101037 | CRITICAL | 9.9 | — | Sep 28, 2026 | A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the... |
| CVE-2026-101036 | MEDIUM | 5.3 | — | Sep 28, 2026 | A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.joi... |
| CVE-2026-101035 | MEDIUM | 5.3 | — | Sep 28, 2026 | A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library sr... |
| CVE-2026-101018 | MEDIUM | 4.7 | — | Sep 28, 2026 | A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the fi... |
| CVE-2026-95104 | HIGH | 7.5 | — | Sep 28, 2026 | Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may... |
| CVE-2026-94287 | MEDIUM | 5.5 | — | Sep 28, 2026 | A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attacke... |
| CVE-2026-94286 | HIGH | 7.1 | — | Sep 28, 2026 | An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to c... |
| CVE-2026-94285 | MEDIUM | 5.1 | — | Sep 28, 2026 | An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X serv... |
| CVE-2026-94284 | MEDIUM | 5.5 | — | Sep 28, 2026 | An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be use... |
| CVE-2026-94283 | MEDIUM | 6.5 | — | Sep 28, 2026 | An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be u... |
| CVE-2026-94282 | MEDIUM | 5.6 | — | Sep 28, 2026 | An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by maliciou... |
| CVE-2026-86530 | HIGH | 7.2 | — | Sep 28, 2026 | BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrat... |
| CVE-2026-86507 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-a... |
| CVE-2026-85134 | HIGH | 8.8 | — | Sep 28, 2026 | Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document a... |
| CVE-2026-82969 | MEDIUM | 5.4 | — | Sep 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution So... |
| CVE-2026-82915 | MEDIUM | 6.5 | — | Sep 28, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now