2026 CVE Vulnerabilities

49,191 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-36607HIGH8.8Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP ...
CVE-2026-36606HIGH7.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key ...
CVE-2026-36603HIGH8.1Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication...
CVE-2026-20230HIGH8.6A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...
CVE-2026-6657HIGH8.8A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe...
CVE-2026-44281HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-42321HIGH8.4GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech...
CVE-2026-42318HIGH7GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11....
CVE-2026-42317HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-37462HIGH7.5An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a...
CVE-2026-36574HIGH7.8A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e...
CVE-2026-44545HIGH7.5daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca...
CVE-2026-37460HIGH7.5Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all...
CVE-2026-35085HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces...
CVE-2026-35084HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ...
CVE-2026-35083HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082HIGH8.8The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient...
CVE-2026-35081HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien...
CVE-2026-35080HIGH8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic...
CVE-2026-35079HIGH8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient...
CVE-2026-35078HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien...
CVE-2026-35077HIGH8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi...
CVE-2026-35076HIGH8.1The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici...
CVE-2026-41032HIGH7.5It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some...
CVE-2026-4035HIGH7.7A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now