2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101017 | MEDIUM | 6.5 | — | Sep 28, 2026 | A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strca... |
| CVE-2026-101016 | MEDIUM | 6.5 | — | Sep 28, 2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_poli... |
| CVE-2026-101015 | HIGH | 7.3 | — | Sep 28, 2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functional... |
| CVE-2026-101014 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the func... |
| CVE-2026-91206 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a rem... |
| CVE-2026-91204 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an an... |
| CVE-2026-82546 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an un... |
| CVE-2026-82387 | MEDIUM | 5.4 | 0.2% | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a use... |
| CVE-2026-82386 | HIGH | 7.7 | 0.3% | Sep 28, 2026 | Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files... |
| CVE-2026-82385 | MEDIUM | 6.5 | 0.3% | Sep 28, 2026 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read ... |
| CVE-2026-82384 | CRITICAL | 9.8 | — | Sep 28, 2026 | Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserializat... |
| CVE-2026-82383 | HIGH | 8.2 | — | Sep 28, 2026 | Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persist... |
| CVE-2026-82382 | MEDIUM | 6.1 | — | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a rem... |
| CVE-2026-82381 | MEDIUM | 5.4 | — | Sep 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a use... |
| CVE-2026-82380 | HIGH | 8.1 | — | Sep 28, 2026 | Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform s... |
| CVE-2026-82379 | HIGH | 7.7 | 0.4% | Sep 28, 2026 | Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authe... |
| CVE-2026-82378 | CRITICAL | 9 | 0.4% | Sep 28, 2026 | Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote... |
| CVE-2026-82377 | CRITICAL | 9.9 | 0.5% | Sep 28, 2026 | Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belo... |
| CVE-2026-82376 | HIGH | 7.7 | 0.3% | Sep 28, 2026 | Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on ... |
| CVE-2026-82375 | HIGH | 7.4 | — | Sep 28, 2026 | Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a we... |
| CVE-2026-82348 | HIGH | 7.7 | 0.4% | Sep 28, 2026 | Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring righ... |
| CVE-2026-101013 | HIGH | 7.3 | — | Sep 28, 2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db... |
| CVE-2026-101012 | HIGH | 7.3 | — | Sep 28, 2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-101011 | MEDIUM | 4.7 | — | Sep 28, 2026 | A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the fi... |
| CVE-2026-101010 | MEDIUM | 4.7 | — | Sep 28, 2026 | A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now