2026 CVE Vulnerabilities
46,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0773 | CRITICAL | 9.8 | 1.1% | Jan 23, 2026 | Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2026-0770 | CRITICAL | 9.8 | 10.4% | Jan 23, 2026 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This... |
| CVE-2026-0769 | CRITICAL | 9.8 | 33.8% | Jan 23, 2026 | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2026-0768 | CRITICAL | 9.8 | 2.0% | Jan 23, 2026 | Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ... |
| CVE-2026-0764 | CRITICAL | 9.8 | 1.0% | Jan 23, 2026 | GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2026-0763 | CRITICAL | 9.8 | 1.0% | Jan 23, 2026 | GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This ... |
| CVE-2026-0761 | CRITICAL | 9.8 | 1.1% | Jan 23, 2026 | Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerabi... |
| CVE-2026-0760 | CRITICAL | 9.8 | 1.0% | Jan 23, 2026 | Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. Thi... |
| CVE-2026-0759 | CRITICAL | 9.8 | 1.7% | Jan 23, 2026 | Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulner... |
| CVE-2026-0756 | CRITICAL | 9.8 | 1.8% | Jan 23, 2026 | github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2026-0755 | CRITICAL | 9.8 | 3.3% | Jan 23, 2026 | gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-24304 | CRITICAL | 9.9 | 0.6% | Jan 23, 2026 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-24132 | CRITICAL | 9.8 | 0.7% | Jan 23, 2026 | Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.... |
| CVE-2026-24306 | CRITICAL | 9.8 | 0.8% | Jan 22, 2026 | Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-24305 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-24124 | CRITICAL | 9.8 | 0.7% | Jan 22, 2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,... |
| CVE-2026-21227 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-24058 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication ... |
| CVE-2026-20912 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a ... |
| CVE-2026-20897 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos... |
| CVE-2026-20750 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate project ownership in organization project operations. A user with project write access ... |
| CVE-2026-1201 | CRITICAL | 9.4 | 0.5% | Jan 22, 2026 | An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior... |
| CVE-2026-22278 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v... |
| CVE-2026-24009 | CRITICAL | 9.8 | 1.4% | Jan 22, 2026 | Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing ... |
| CVE-2026-23760 | CRITICAL | 9.8 | 96.3% | Jan 22, 2026 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password res... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now