2026 CVE Vulnerabilities
47,667 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46248 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->li... |
| CVE-2026-46247 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map ... |
| CVE-2026-46245 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD i... |
| CVE-2026-39107 | MEDIUM | 6.3 | 0.3% | Jun 3, 2026 | A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails... |
| CVE-2026-36618 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS ... |
| CVE-2026-36616 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s... |
| CVE-2026-36615 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns... |
| CVE-2026-36613 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents whe... |
| CVE-2026-36612 | MEDIUM | 6.4 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon... |
| CVE-2026-36610 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64... |
| CVE-2026-36605 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low numb... |
| CVE-2026-36604 | MEDIUM | 6.5 | 0.3% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS reb... |
| CVE-2026-36602 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInf... |
| CVE-2026-36460 | MEDIUM | 4.8 | 0.2% | Jun 3, 2026 | Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save ... |
| CVE-2026-20233 | MEDIUM | 6.1 | 0.2% | Jun 3, 2026 | A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote at... |
| CVE-2026-20175 | MEDIUM | 6.1 | 0.2% | Jun 3, 2026 | A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote loc... |
| CVE-2026-42320 | MEDIUM | 5.9 | 0.2% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-3276 | MEDIUM | 6.3 | 0.5% | Jun 3, 2026 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs... |
| CVE-2026-8404 | MEDIUM | 5.3 | 0.3% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware... |
| CVE-2026-6873 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in... |
| CVE-2026-48587 | MEDIUM | 5.3 | 0.4% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan... |
| CVE-2026-47325 | MEDIUM | 6.9 | 0.2% | Jun 3, 2026 | ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password... |
| CVE-2026-47324 | MEDIUM | 5.1 | 0.3% | Jun 3, 2026 | ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o... |
| CVE-2026-44546 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket... |
| CVE-2026-10722 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now