2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23522 | LOW | 3.7 | 0.2% | Jan 19, 2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno... |
| CVE-2026-1161 | LOW | 3.5 | 0.2% | Jan 19, 2026 | A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil... |
| CVE-2026-1136 | LOW | 3.5 | 0.2% | Jan 19, 2026 | A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio... |
| CVE-2026-0682 | LOW | 2.2 | 0.2% | Jan 17, 2026 | The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,... |
| CVE-2026-0519 | LOW | 3.4 | 0.1% | Jan 17, 2026 | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u... |
| CVE-2026-0992 | LOW | 2.9 | 0.3% | Jan 15, 2026 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML... |
| CVE-2026-0989 | LOW | 3.7 | 0.4% | Jan 15, 2026 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser... |
| CVE-2026-0976 | LOW | 3.7 | 0.4% | Jan 15, 2026 | A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant... |
| CVE-2026-22819 | LOW | 3.1 | 0.2% | Jan 14, 2026 | Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more t... |
| CVE-2026-22820 | LOW | 3.7 | 0.2% | Jan 14, 2026 | Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the s... |
| CVE-2026-0510 | LOW | 3 | 0.1% | Jan 13, 2026 | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi... |
| CVE-2026-0504 | LOW | 3.8 | 0.2% | Jan 13, 2026 | Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to ... |
| CVE-2026-0824 | LOW | 3.5 | 0.2% | Jan 10, 2026 | A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con... |
| CVE-2026-22611 | LOW | 3.7 | 0.2% | Jan 10, 2026 | AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon... |
| CVE-2026-22597 | LOW | 2.7 | 0.3% | Jan 10, 2026 | Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili... |
| CVE-2026-22602 | LOW | 3.5 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-i... |
| CVE-2026-22025 | LOW | 3.7 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-20972 | LOW | 3.3 | 0.1% | Jan 9, 2026 | Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to e... |
| CVE-2026-22714 | LOW | 2.3 | 0.3% | Jan 9, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2026-0747 | LOW | 3.3 | 0.2% | Jan 8, 2026 | Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now