2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24656 | LOW | 3.7 | 0.7% | Jan 26, 2026 | Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes th... |
| CVE-2026-1417 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file app... |
| CVE-2026-1416 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of... |
| CVE-2026-1415 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file... |
| CVE-2026-1406 | LOW | 3.5 | 0.2% | Jan 25, 2026 | A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulner... |
| CVE-2026-0633 | LOW | 3.7 | 0.2% | Jan 24, 2026 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens... |
| CVE-2026-22978 | LOW | 3.3 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point s... |
| CVE-2026-24515 | LOW | 2.5 | 0.2% | Jan 23, 2026 | In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. |
| CVE-2026-0798 | LOW | 3.5 | 0.2% | Jan 22, 2026 | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos... |
| CVE-2026-22411 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr... |
| CVE-2026-22409 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco... |
| CVE-2026-22407 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly ... |
| CVE-2026-22406 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr... |
| CVE-2026-22404 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr... |
| CVE-2026-1225 | LOW | 1.8 | 0.2% | Jan 22, 2026 | ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java ap... |
| CVE-2026-24048 | LOW | 3.7 | 0.2% | Jan 21, 2026 | Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl... |
| CVE-2026-23996 | LOW | 3.7 | 0.3% | Jan 21, 2026 | FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-cha... |
| CVE-2026-0988 | LOW | 3.7 | 0.4% | Jan 21, 2026 | A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() functi... |
| CVE-2026-1035 | LOW | 3.1 | 0.3% | Jan 21, 2026 | A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi... |
| CVE-2026-21977 | LOW | 3.1 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Applian... |
| CVE-2026-21965 | LOW | 2.7 | 0.3% | Jan 20, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that ... |
| CVE-2026-21947 | LOW | 3.1 | 0.2% | Jan 20, 2026 | Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50... |
| CVE-2026-21930 | LOW | 2.3 | 0.1% | Jan 20, 2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte... |
| CVE-2026-21640 | LOW | 2.7 | 0.2% | Jan 20, 2026 | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti... |
| CVE-2026-1197 | LOW | 3.1 | 0.3% | Jan 20, 2026 | A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now