2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2069 | LOW | 3.3 | 0.1% | Feb 6, 2026 | A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the f... |
| CVE-2026-25764 | LOW | 3.5 | 0.2% | Feb 6, 2026 | OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injec... |
| CVE-2026-22254 | LOW | 3.5 | 0.3% | Feb 6, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS... |
| CVE-2026-1990 | LOW | 3.3 | 0.2% | Feb 6, 2026 | A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap... |
| CVE-2026-25815 | LOW | 3.2 | 0.1% | Feb 5, 2026 | Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp... |
| CVE-2026-1966 | LOW | 2.4 | 0.2% | Feb 5, 2026 | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated ... |
| CVE-2026-25517 | LOW | 2.7 | 0.3% | Feb 4, 2026 | Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7... |
| CVE-2026-20730 | LOW | 3.3 | 0.1% | Feb 4, 2026 | A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access ... |
| CVE-2026-1791 | LOW | 2.7 | 0.3% | Feb 4, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G... |
| CVE-2026-24513 | LOW | 3.1 | 0.3% | Feb 3, 2026 | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may ... |
| CVE-2026-25224 | LOW | 3.7 | 0.5% | Feb 3, 2026 | Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability... |
| CVE-2026-24934 | LOW | 3.7 | 0.2% | Feb 3, 2026 | The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an externa... |
| CVE-2026-1703 | LOW | 2 | 0.4% | Feb 2, 2026 | When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installati... |
| CVE-2026-1751 | LOW | 3.1 | 0.2% | Feb 2, 2026 | A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h... |
| CVE-2026-1743 | LOW | 3.1 | 0.4% | Feb 2, 2026 | A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit... |
| CVE-2026-1705 | LOW | 2.4 | 0.2% | Jan 30, 2026 | A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_se... |
| CVE-2026-25211 | LOW | 3.2 | 0.2% | Jan 30, 2026 | Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. |
| CVE-2026-25046 | LOW | 2.9 | 0.1% | Jan 29, 2026 | Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publis... |
| CVE-2026-1588 | LOW | 2.7 | 0.6% | Jan 29, 2026 | A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshE... |
| CVE-2026-23553 | LOW | 2.9 | 0.1% | Jan 28, 2026 | In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the pr... |
| CVE-2026-1520 | LOW | 2.4 | 0.2% | Jan 28, 2026 | A vulnerability was identified in rethinkdb up to 2.4.3. Affected by this issue is some unknown functionality of the com... |
| CVE-2026-1237 | LOW | 2.1 | 0.1% | Jan 28, 2026 | Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us... |
| CVE-2026-1485 | LOW | 2.8 | 0.1% | Jan 27, 2026 | A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of ... |
| CVE-2026-1444 | LOW | 2.4 | 0.2% | Jan 26, 2026 | A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects ... |
| CVE-2026-1190 | LOW | 3.1 | 0.4% | Jan 26, 2026 | A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Asser... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now