2026 CVE Vulnerabilities
46,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24132 | CRITICAL | 9.8 | 0.7% | Jan 23, 2026 | Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.... |
| CVE-2026-24306 | CRITICAL | 9.8 | 0.8% | Jan 22, 2026 | Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-24305 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-24124 | CRITICAL | 9.8 | 0.7% | Jan 22, 2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,... |
| CVE-2026-21227 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-24058 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication ... |
| CVE-2026-20912 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a ... |
| CVE-2026-20897 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos... |
| CVE-2026-20750 | CRITICAL | 9.1 | 0.4% | Jan 22, 2026 | Gitea does not properly validate project ownership in organization project operations. A user with project write access ... |
| CVE-2026-1201 | CRITICAL | 9.4 | 0.5% | Jan 22, 2026 | An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior... |
| CVE-2026-22278 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v... |
| CVE-2026-24009 | CRITICAL | 9.8 | 1.4% | Jan 22, 2026 | Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing ... |
| CVE-2026-23760 | CRITICAL | 9.8 | 96.3% | Jan 22, 2026 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password res... |
| CVE-2026-1325 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This a... |
| CVE-2026-1324 | CRITICAL | 9.8 | 6.4% | Jan 22, 2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this iss... |
| CVE-2026-1331 | CRITICAL | 9.8 | 0.7% | Jan 22, 2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote ... |
| CVE-2026-0920 | CRITICAL | 9.8 | 1.1% | Jan 22, 2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio... |
| CVE-2026-24042 | CRITICAL | 9.8 | 0.6% | Jan 22, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly acces... |
| CVE-2026-24002 | CRITICAL | 9.6 | 0.5% | Jan 22, 2026 | Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formu... |
| CVE-2026-23966 | CRITICAL | 9.1 | 0.2% | Jan 22, 2026 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key r... |
| CVE-2026-23958 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the... |
| CVE-2026-23873 | CRITICAL | 9 | 0.5% | Jan 22, 2026 | hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vuln... |
| CVE-2026-23736 | CRITICAL | 9.8 | 0.2% | Jan 21, 2026 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio... |
| CVE-2026-23524 | CRITICAL | 9.8 | 0.9% | Jan 21, 2026 | Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and belo... |
| CVE-2026-23518 | CRITICAL | 9.8 | 0.2% | Jan 21, 2026 | Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vuln... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now