2026 CVE Vulnerabilities
47,106 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1107 | CRITICAL | 9.8 | 0.5% | Jan 18, 2026 | A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.p... |
| CVE-2026-1105 | CRITICAL | 9.8 | 0.4% | Jan 18, 2026 | A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.cla... |
| CVE-2026-1062 | CRITICAL | 9.8 | 0.4% | Jan 17, 2026 | A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lh... |
| CVE-2026-1061 | CRITICAL | 9.8 | 0.4% | Jan 17, 2026 | A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file s... |
| CVE-2026-1059 | CRITICAL | 9.8 | 0.4% | Jan 17, 2026 | A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by th... |
| CVE-2026-23800 | CRITICAL | 10 | 0.5% | Jan 16, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe... |
| CVE-2026-23744 | CRITICAL | 9.8 | 38.4% | Jan 16, 2026 | MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to r... |
| CVE-2026-0975 | CRITICAL | 9.8 | 1.4% | Jan 16, 2026 | Delta Electronics DIAView has Command Injection vulnerability. |
| CVE-2026-22864 | CRITICAL | 9.8 | 0.6% | Jan 15, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows b... |
| CVE-2026-23746 | CRITICAL | 9.3 | 0.9% | Jan 15, 2026 | Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to... |
| CVE-2026-23527 | CRITICAL | 9.8 | 0.6% | Jan 15, 2026 | H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP R... |
| CVE-2026-23519 | CRITICAL | 9.8 | 0.5% | Jan 15, 2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-... |
| CVE-2026-22249 | CRITICAL | 9.8 | 0.5% | Jan 15, 2026 | Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulner... |
| CVE-2026-22910 | CRITICAL | 9.1 | 0.4% | Jan 15, 2026 | The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris... |
| CVE-2026-22909 | CRITICAL | 9.1 | 0.5% | Jan 15, 2026 | Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete inst... |
| CVE-2026-22908 | CRITICAL | 9.1 | 0.5% | Jan 15, 2026 | Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially comprom... |
| CVE-2026-22907 | CRITICAL | 9.1 | 0.4% | Jan 15, 2026 | An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system dat... |
| CVE-2026-22859 | CRITICAL | 9.1 | 0.8% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bou... |
| CVE-2026-22858 | CRITICAL | 9.1 | 0.6% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in... |
| CVE-2026-22857 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_th... |
| CVE-2026-22855 | CRITICAL | 9.1 | 0.8% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in th... |
| CVE-2026-22854 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive... |
| CVE-2026-22853 | CRITICAL | 9.8 | 0.7% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not per... |
| CVE-2026-22852 | CRITICAL | 9.8 | 0.4% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a h... |
| CVE-2026-22708 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now