2026 CVE Vulnerabilities
46,943 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1589 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil... |
| CVE-2026-1188 | CRITICAL | 9.8 | 0.5% | Jan 29, 2026 | In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all suppor... |
| CVE-2026-1552 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_In... |
| CVE-2026-24888 | CRITICAL | 9.8 | 0.9% | Jan 28, 2026 | Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.... |
| CVE-2026-24857 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar co... |
| CVE-2026-1547 | CRITICAL | 9.8 | 2.8% | Jan 28, 2026 | A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi... |
| CVE-2026-1546 | CRITICAL | 9.8 | 0.3% | Jan 28, 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillI... |
| CVE-2026-1545 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function... |
| CVE-2026-24769 | CRITICAL | 9 | 0.4% | Jan 28, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)... |
| CVE-2026-1535 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of t... |
| CVE-2026-1534 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Adm... |
| CVE-2026-1533 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ... |
| CVE-2026-24772 | CRITICAL | 9 | 0.2% | Jan 28, 2026 | OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents... |
| CVE-2026-1056 | CRITICAL | 9.8 | 12.0% | Jan 28, 2026 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida... |
| CVE-2026-24841 | CRITICAL | 9.9 | 2.5% | Jan 28, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection... |
| CVE-2026-24785 | CRITICAL | 9.1 | 0.1% | Jan 28, 2026 | Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Vers... |
| CVE-2026-23830 | CRITICAL | 10 | 1.1% | Jan 28, 2026 | SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `Async... |
| CVE-2026-24770 | CRITICAL | 9.8 | 0.9% | Jan 27, 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, ... |
| CVE-2026-24740 | CRITICAL | 9.9 | 0.4% | Jan 27, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell end... |
| CVE-2026-24858 | CRITICAL | 9.8 | 85.8% | Jan 27, 2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnaly... |
| CVE-2026-24881 | CRITICAL | 9.8 | 1.7% | Jan 27, 2026 | In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause... |
| CVE-2026-22264 | CRITICAL | 9.1 | 0.3% | Jan 27, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead ... |
| CVE-2026-22262 | CRITICAL | 9.8 | 0.5% | Jan 27, 2026 | Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior ... |
| CVE-2026-22039 | CRITICAL | 9.9 | 0.5% | Jan 27, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav... |
| CVE-2026-24874 | CRITICAL | 9.1 | 0.3% | Jan 27, 2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now