2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101279 | MEDIUM | 6.5 | — | Sep 29, 2026 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown func... |
| CVE-2026-101278 | MEDIUM | 4.3 | — | Sep 29, 2026 | A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_... |
| CVE-2026-18747 | MEDIUM | 6.8 | — | Sep 29, 2026 | The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and t... |
| CVE-2026-18746 | MEDIUM | 5.9 | — | Sep 29, 2026 | parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry ... |
| CVE-2026-18417 | MEDIUM | 6.5 | — | Sep 29, 2026 | The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's vo... |
| CVE-2026-102367 | MEDIUM | 5.4 | — | Sep 29, 2026 | mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to... |
| CVE-2026-102366 | MEDIUM | 4.4 | — | Sep 29, 2026 | mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorizatio... |
| CVE-2026-102365 | MEDIUM | 6.5 | — | Sep 29, 2026 | mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer a... |
| CVE-2026-102364 | MEDIUM | 5.4 | — | Sep 29, 2026 | mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authentica... |
| CVE-2026-102363 | LOW | 3.7 | — | Sep 29, 2026 | mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that... |
| CVE-2026-102362 | MEDIUM | 5.3 | — | Sep 29, 2026 | mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Un... |
| CVE-2026-102361 | CRITICAL | 9.1 | — | Sep 29, 2026 | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unaut... |
| CVE-2026-101277 | MEDIUM | 6.5 | — | Sep 29, 2026 | A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the functio... |
| CVE-2026-101265 | LOW | 3.1 | — | Sep 29, 2026 | A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the c... |
| CVE-2026-101264 | CRITICAL | 9.1 | — | Sep 29, 2026 | A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork... |
| CVE-2026-101263 | CRITICAL | 9.1 | — | Sep 29, 2026 | A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQ... |
| CVE-2026-102335 | HIGH | 7.1 | — | Sep 28, 2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin use... |
| CVE-2026-102334 | HIGH | 7.4 | — | Sep 28, 2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers t... |
| CVE-2026-102333 | MEDIUM | 6.1 | — | Sep 28, 2026 | httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web ... |
| CVE-2026-102332 | MEDIUM | 6.1 | — | Sep 28, 2026 | Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log ... |
| CVE-2026-101262 | CRITICAL | 9.1 | — | Sep 28, 2026 | A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/Z... |
| CVE-2026-101261 | CRITICAL | 9.1 | — | Sep 28, 2026 | A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_... |
| CVE-2026-101260 | CRITICAL | 9.1 | — | Sep 28, 2026 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the ... |
| CVE-2026-102297 | MEDIUM | 4.3 | — | Sep 28, 2026 | ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenti... |
| CVE-2026-102296 | MEDIUM | 6.5 | — | Sep 28, 2026 | ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now