2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-101017MEDIUM6.5A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strca...
CVE-2026-101016MEDIUM6.5A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_poli...
CVE-2026-101015HIGH7.3A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functional...
CVE-2026-101014HIGH7.3A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the func...
CVE-2026-91206MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a rem...
CVE-2026-91204MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an an...
CVE-2026-82546MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an un...
CVE-2026-82387MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a use...
CVE-2026-82386HIGH7.7Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files...
CVE-2026-82385MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read ...
CVE-2026-82384CRITICAL9.8Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserializat...
CVE-2026-82383HIGH8.2Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persist...
CVE-2026-82382MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a rem...
CVE-2026-82381MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a use...
CVE-2026-82380HIGH8.1Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform s...
CVE-2026-82379HIGH7.7Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authe...
CVE-2026-82378CRITICAL9Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote...
CVE-2026-82377CRITICAL9.9Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belo...
CVE-2026-82376HIGH7.7Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on ...
CVE-2026-82375HIGH7.4Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a we...
CVE-2026-82348HIGH7.7Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring righ...
CVE-2026-101013HIGH7.3A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db...
CVE-2026-101012HIGH7.3A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-101011MEDIUM4.7A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the fi...
CVE-2026-101010MEDIUM4.7A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now