2026 CVE Vulnerabilities

47,667 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46248MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->li...
CVE-2026-46247MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map ...
CVE-2026-46245MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD i...
CVE-2026-39107MEDIUM6.3A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails...
CVE-2026-36618MEDIUM4.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS ...
CVE-2026-36616MEDIUM5.9Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s...
CVE-2026-36615MEDIUM4.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns...
CVE-2026-36613MEDIUM4.3Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents whe...
CVE-2026-36612MEDIUM6.4Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon...
CVE-2026-36610MEDIUM5.9Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64...
CVE-2026-36605MEDIUM6.5Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low numb...
CVE-2026-36604MEDIUM6.5Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS reb...
CVE-2026-36602MEDIUM4.3Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInf...
CVE-2026-36460MEDIUM4.8Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save ...
CVE-2026-20233MEDIUM6.1A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote at...
CVE-2026-20175MEDIUM6.1A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote loc...
CVE-2026-42320MEDIUM5.9GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0...
CVE-2026-3276MEDIUM6.3unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs...
CVE-2026-8404MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware...
CVE-2026-6873MEDIUM4.3An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in...
CVE-2026-48587MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan...
CVE-2026-47325MEDIUM6.9ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password...
CVE-2026-47324MEDIUM5.1ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o...
CVE-2026-44546MEDIUM5.3daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket...
CVE-2026-10722MEDIUM5.5A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now