2026 CVE Vulnerabilities
53,398 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23022 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vc_core_deinit() Mak... |
| CVE-2026-23021 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_re... |
| CVE-2026-23020 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: 3com: 3c59x: fix possible null dereference in ... |
| CVE-2026-23019 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on dev... |
| CVE-2026-23018 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: release path before initializing extent tree... |
| CVE-2026-23017 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix error handling in the init_task on load ... |
| CVE-2026-23016 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Ja... |
| CVE-2026-23015 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: fix reference leak in gpio_mpsse_probe... |
| CVE-2026-1251 | MEDIUM | 5.4 | 0.3% | Jan 31, 2026 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec... |
| CVE-2026-0683 | MEDIUM | 6.5 | 0.3% | Jan 31, 2026 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the... |
| CVE-2026-1431 | MEDIUM | 5.3 | 0.3% | Jan 31, 2026 | The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2026-25156 | MEDIUM | 6.3 | 0.2% | Jan 30, 2026 | HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all ... |
| CVE-2026-25154 | MEDIUM | 6.1 | 0.3% | Jan 30, 2026 | LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local ... |
| CVE-2026-25152 | MEDIUM | 6.5 | 0.4% | Jan 30, 2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.... |
| CVE-2026-23835 | MEDIUM | 5.7 | 0.3% | Jan 30, 2026 | LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Ba... |
| CVE-2026-1700 | MEDIUM | 5.4 | 0.2% | Jan 30, 2026 | A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknow... |
| CVE-2026-1690 | MEDIUM | 4.7 | 3.5% | Jan 30, 2026 | A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /b... |
| CVE-2026-25050 | MEDIUM | 5.3 | 0.4% | Jan 30, 2026 | Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenti... |
| CVE-2026-24855 | MEDIUM | 5.4 | 0.2% | Jan 30, 2026 | ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) v... |
| CVE-2026-1685 | MEDIUM | 5.9 | 1.0% | Jan 30, 2026 | A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the comp... |
| CVE-2026-22626 | MEDIUM | 4.9 | 0.4% | Jan 30, 2026 | Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can... |
| CVE-2026-22625 | MEDIUM | 4.6 | 0.2% | Jan 30, 2026 | Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files. |
| CVE-2026-22624 | MEDIUM | 4.3 | 0.2% | Jan 30, 2026 | Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file r... |
| CVE-2026-1665 | MEDIUM | 5.4 | 0.8% | Jan 29, 2026 | A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() fun... |
| CVE-2026-24904 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now