2026 CVE Vulnerabilities
47,166 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22236 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated rem... |
| CVE-2026-23550 | CRITICAL | 9.8 | 20.6% | Jan 14, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This... |
| CVE-2026-22686 | CRITICAL | 10 | 0.6% | Jan 14, 2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sa... |
| CVE-2026-23478 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JW... |
| CVE-2026-22871 | CRITICAL | 9.8 | 0.9% | Jan 13, 2026 | GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exis... |
| CVE-2026-22869 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allow... |
| CVE-2026-20963 | CRITICAL | 9.8 | 31.1% | Jan 13, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ... |
| CVE-2026-22755 | CRITICAL | 9.3 | 21.2% | Jan 13, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected de... |
| CVE-2026-0892 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-0884 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thund... |
| CVE-2026-0881 | CRITICAL | 10 | 0.3% | Jan 13, 2026 | Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
| CVE-2026-0879 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1... |
| CVE-2026-0501 | CRITICAL | 9.9 | 0.4% | Jan 13, 2026 | Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent... |
| CVE-2026-0491 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module ... |
| CVE-2026-22214 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos ... |
| CVE-2026-22213 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapsli... |
| CVE-2026-22785 | CRITICAL | 9.8 | 0.7% | Jan 12, 2026 | orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0... |
| CVE-2026-22781 | CRITICAL | 9.8 | 2.2% | Jan 12, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable... |
| CVE-2026-22252 | CRITICAL | 9.9 | 3.7% | Jan 12, 2026 | LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbi... |
| CVE-2026-0852 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ... |
| CVE-2026-0851 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of th... |
| CVE-2026-0821 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_arra... |
| CVE-2026-22685 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis... |
| CVE-2026-22687 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-22600 | CRITICAL | 9.1 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now