2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-101279MEDIUM6.5A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown func...
CVE-2026-101278MEDIUM4.3A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_...
CVE-2026-18747MEDIUM6.8The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and t...
CVE-2026-18746MEDIUM5.9parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry ...
CVE-2026-18417MEDIUM6.5The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's vo...
CVE-2026-102367MEDIUM5.4mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to...
CVE-2026-102366MEDIUM4.4mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorizatio...
CVE-2026-102365MEDIUM6.5mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer a...
CVE-2026-102364MEDIUM5.4mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authentica...
CVE-2026-102363LOW3.7mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that...
CVE-2026-102362MEDIUM5.3mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Un...
CVE-2026-102361CRITICAL9.1mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unaut...
CVE-2026-101277MEDIUM6.5A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the functio...
CVE-2026-101265LOW3.1A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the c...
CVE-2026-101264CRITICAL9.1A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork...
CVE-2026-101263CRITICAL9.1A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQ...
CVE-2026-102335HIGH7.1Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin use...
CVE-2026-102334HIGH7.4Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers t...
CVE-2026-102333MEDIUM6.1httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web ...
CVE-2026-102332MEDIUM6.1Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log ...
CVE-2026-101262CRITICAL9.1A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/Z...
CVE-2026-101261CRITICAL9.1A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_...
CVE-2026-101260CRITICAL9.1A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the ...
CVE-2026-102297MEDIUM4.3ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenti...
CVE-2026-102296MEDIUM6.5ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now