2026 CVE Vulnerabilities
47,201 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0501 | CRITICAL | 9.9 | 0.4% | Jan 13, 2026 | Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent... |
| CVE-2026-0491 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module ... |
| CVE-2026-22214 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos ... |
| CVE-2026-22213 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapsli... |
| CVE-2026-22785 | CRITICAL | 9.8 | 0.7% | Jan 12, 2026 | orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0... |
| CVE-2026-22781 | CRITICAL | 9.8 | 2.2% | Jan 12, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable... |
| CVE-2026-22252 | CRITICAL | 9.9 | 3.7% | Jan 12, 2026 | LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbi... |
| CVE-2026-0852 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function ... |
| CVE-2026-0851 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of th... |
| CVE-2026-0821 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_arra... |
| CVE-2026-22685 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis... |
| CVE-2026-22687 | CRITICAL | 9.8 | 0.4% | Jan 10, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-22600 | CRITICAL | 9.1 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in th... |
| CVE-2026-22584 | CRITICAL | 9.8 | 0.4% | Jan 9, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux al... |
| CVE-2026-20973 | CRITICAL | 9.1 | 0.4% | Jan 9, 2026 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bou... |
| CVE-2026-0732 | CRITICAL | 9.8 | 10.0% | Jan 9, 2026 | A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.as... |
| CVE-2026-22234 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endp... |
| CVE-2026-22043 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed... |
| CVE-2026-22034 | CRITICAL | 9.8 | 0.7% | Jan 8, 2026 | Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual... |
| CVE-2026-21891 | CRITICAL | 9.8 | 2.2% | Jan 8, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and inc... |
| CVE-2026-0700 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function... |
| CVE-2026-21881 | CRITICAL | 9.1 | 0.4% | Jan 8, 2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a crit... |
| CVE-2026-21877 | CRITICAL | 9.9 | 5.3% | Jan 8, 2026 | n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able... |
| CVE-2026-21875 | CRITICAL | 9.8 | 0.3% | Jan 8, 2026 | ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind... |
| CVE-2026-21869 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is par... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now