2026 CVE Vulnerabilities
49,191 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36607 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ... |
| CVE-2026-36606 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ... |
| CVE-2026-36603 | HIGH | 8.1 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication... |
| CVE-2026-20230 | HIGH | 8.6 | 41.7% | Jun 3, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
| CVE-2026-6657 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe... |
| CVE-2026-44281 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-42321 | HIGH | 8.4 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech... |
| CVE-2026-42318 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.... |
| CVE-2026-42317 | HIGH | 7 | 0.3% | Jun 3, 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0... |
| CVE-2026-37462 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a... |
| CVE-2026-36574 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e... |
| CVE-2026-44545 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca... |
| CVE-2026-37460 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all... |
| CVE-2026-35085 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces... |
| CVE-2026-35084 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ... |
| CVE-2026-35083 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. |
| CVE-2026-35082 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient... |
| CVE-2026-35081 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien... |
| CVE-2026-35080 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic... |
| CVE-2026-35079 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient... |
| CVE-2026-35078 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien... |
| CVE-2026-35077 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi... |
| CVE-2026-35076 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici... |
| CVE-2026-41032 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some... |
| CVE-2026-4035 | HIGH | 7.7 | 0.4% | Jun 3, 2026 | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now