2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92213 | MEDIUM | 5.5 | 0.2% | Sep 16, 2026 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/we... |
| CVE-2026-92184 | MEDIUM | 6.3 | 0.3% | Sep 16, 2026 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of th... |
| CVE-2026-73460 | MEDIUM | 6.1 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject... |
| CVE-2026-92259 | MEDIUM | 5.5 | 0.2% | Sep 15, 2026 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the by... |
| CVE-2026-92257 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages t... |
| CVE-2026-92256 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_s... |
| CVE-2026-92255 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by imp... |
| CVE-2026-92114 | MEDIUM | 5.3 | 0.5% | Sep 15, 2026 | A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/... |
| CVE-2026-82567 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a conn... |
| CVE-2026-76873 | MEDIUM | 5.2 | 0.2% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display a... |
| CVE-2026-76872 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL man... |
| CVE-2026-76871 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json... |
| CVE-2026-76868 | MEDIUM | 4.9 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a... |
| CVE-2026-76867 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT conf... |
| CVE-2026-76865 | MEDIUM | 4.9 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filt... |
| CVE-2026-76864 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_... |
| CVE-2026-76863 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth pl... |
| CVE-2026-76859 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi c... |
| CVE-2026-76858 | MEDIUM | 4.8 | 0.3% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused... |
| CVE-2026-76857 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_li... |
| CVE-2026-76855 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints hand... |
| CVE-2026-76854 | MEDIUM | 6.5 | 0.5% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cg... |
| CVE-2026-73444 | MEDIUM | 4.7 | 0.3% | Sep 15, 2026 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unau... |
| CVE-2026-92237 | MEDIUM | 6.5 | 0.1% | Sep 15, 2026 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2... |
| CVE-2026-92234 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Res... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now