2026 CVE Vulnerabilities
46,942 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24471 | CRITICAL | 9.3 | 0.3% | Feb 2, 2026 | continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote serve... |
| CVE-2026-23997 | CRITICAL | 9 | 0.4% | Feb 2, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro... |
| CVE-2026-22778 | CRITICAL | 9.8 | 3.8% | Feb 2, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid i... |
| CVE-2026-20418 | CRITICAL | 9.8 | 0.3% | Feb 2, 2026 | In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation o... |
| CVE-2026-20407 | CRITICAL | 9.3 | 0.2% | Feb 2, 2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local ... |
| CVE-2026-25202 | CRITICAL | 9.8 | 0.4% | Feb 2, 2026 | The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo... |
| CVE-2026-25200 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto... |
| CVE-2026-1740 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file ... |
| CVE-2026-25069 | CRITICAL | 9.3 | 0.6% | Feb 1, 2026 | SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log ... |
| CVE-2026-25141 | CRITICAL | 9.8 | 0.6% | Jan 30, 2026 | Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starti... |
| CVE-2026-25130 | CRITICAL | 9.6 | 0.8% | Jan 30, 2026 | Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI... |
| CVE-2026-1723 | CRITICAL | 9.2 | 0.9% | Jan 30, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2026-1701 | CRITICAL | 9.8 | 0.4% | Jan 30, 2026 | A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown... |
| CVE-2026-1688 | CRITICAL | 9.8 | 0.3% | Jan 30, 2026 | A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an u... |
| CVE-2026-24729 | CRITICAL | 10 | 0.3% | Jan 30, 2026 | An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker ver... |
| CVE-2026-24728 | CRITICAL | 9.3 | 0.4% | Jan 30, 2026 | A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker ... |
| CVE-2026-1340 | CRITICAL | 9.8 | 84.0% | Jan 29, 2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. |
| CVE-2026-1281 | CRITICAL | 9.8 | 81.2% | Jan 29, 2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. |
| CVE-2026-22806 | CRITICAL | 9.1 | 0.4% | Jan 29, 2026 | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio... |
| CVE-2026-1453 | CRITICAL | 9.8 | 0.5% | Jan 29, 2026 | A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated a... |
| CVE-2026-24054 | CRITICAL | 10 | 0.4% | Jan 29, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-1595 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /ad... |
| CVE-2026-1594 | CRITICAL | 9.8 | 0.5% | Jan 29, 2026 | A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some... |
| CVE-2026-1593 | CRITICAL | 9.8 | 0.5% | Jan 29, 2026 | A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-1590 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now