2026 CVE Vulnerabilities
46,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22807 | CRITICAL | 9.8 | 0.7% | Jan 21, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio... |
| CVE-2026-22793 | CRITICAL | 9.6 | 0.6% | Jan 21, 2026 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0... |
| CVE-2026-22792 | CRITICAL | 9.6 | 0.7% | Jan 21, 2026 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0... |
| CVE-2026-20045 | CRITICAL | 9.8 | 4.3% | Jan 21, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag... |
| CVE-2026-24061 | CRITICAL | 9.8 | 98.9% | Jan 21, 2026 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment ... |
| CVE-2026-0933 | CRITICAL | 9.9 | 1.4% | Jan 20, 2026 | SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The is... |
| CVE-2026-21969 | CRITICAL | 9.8 | 0.4% | Jan 20, 2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Su... |
| CVE-2026-21962 | CRITICAL | 10 | 42.7% | Jan 20, 2026 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo... |
| CVE-2026-21636 | CRITICAL | 10 | 0.7% | Jan 20, 2026 | A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--... |
| CVE-2026-22844 | CRITICAL | 9.9 | 13.0% | Jan 20, 2026 | A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting p... |
| CVE-2026-1221 | CRITICAL | 9.8 | 0.4% | Jan 20, 2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowi... |
| CVE-2026-0907 | CRITICAL | 9.8 | 0.2% | Jan 20, 2026 | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo... |
| CVE-2026-0906 | CRITICAL | 9.8 | 0.3% | Jan 20, 2026 | Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content... |
| CVE-2026-0905 | CRITICAL | 9.8 | 0.2% | Jan 20, 2026 | Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a netw... |
| CVE-2026-23947 | CRITICAL | 9.8 | 0.8% | Jan 20, 2026 | Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior ... |
| CVE-2026-23876 | CRITICAL | 9.8 | 0.6% | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-22770 | CRITICAL | 9.8 | 0.3% | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage me... |
| CVE-2026-1202 | CRITICAL | 9.8 | 0.8% | Jan 20, 2026 | A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file cr... |
| CVE-2026-1179 | CRITICAL | 9.8 | 0.4% | Jan 19, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the c... |
| CVE-2026-23944 | CRITICAL | 9.8 | 0.4% | Jan 19, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthent... |
| CVE-2026-23885 | CRITICAL | 9.9 | 0.4% | Jan 19, 2026 | Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3,... |
| CVE-2026-1178 | CRITICAL | 9.8 | 0.4% | Jan 19, 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of t... |
| CVE-2026-1177 | CRITICAL | 9.8 | 0.4% | Jan 19, 2026 | A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the fil... |
| CVE-2026-23837 | CRITICAL | 9.8 | 0.6% | Jan 19, 2026 | MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and ... |
| CVE-2026-1176 | CRITICAL | 9.8 | 0.3% | Jan 19, 2026 | A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now