2026 CVE Vulnerabilities
53,401 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1665 | MEDIUM | 5.4 | 0.8% | Jan 29, 2026 | A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() fun... |
| CVE-2026-24904 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, ... |
| CVE-2026-24846 | MEDIUM | 5 | 0.2% | Jan 29, 2026 | malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8... |
| CVE-2026-24845 | MEDIUM | 6.5 | 0.3% | Jan 29, 2026 | malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.1... |
| CVE-2026-1623 | MEDIUM | 6.3 | 2.0% | Jan 29, 2026 | A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin... |
| CVE-2026-25068 | MEDIUM | 4.6 | 0.2% | Jan 29, 2026 | alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in t... |
| CVE-2026-24687 | MEDIUM | 6.5 | 0.4% | Jan 29, 2026 | Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent... |
| CVE-2026-1601 | MEDIUM | 6.3 | 1.8% | Jan 29, 2026 | A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of ... |
| CVE-2026-24414 | MEDIUM | 5.5 | 0.1% | Jan 29, 2026 | The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of W... |
| CVE-2026-24413 | MEDIUM | 5.5 | 0.1% | Jan 29, 2026 | Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.... |
| CVE-2026-1600 | MEDIUM | 4.3 | 0.3% | Jan 29, 2026 | A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted ele... |
| CVE-2026-1599 | MEDIUM | 4.3 | 0.3% | Jan 29, 2026 | A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected ele... |
| CVE-2026-1598 | MEDIUM | 5.4 | 0.2% | Jan 29, 2026 | A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknow... |
| CVE-2026-0936 | MEDIUM | 5.1 | 0.1% | Jan 29, 2026 | An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused ... |
| CVE-2026-1469 | MEDIUM | 5.4 | 0.1% | Jan 29, 2026 | Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript... |
| CVE-2026-22764 | MEDIUM | 6.5 | 0.2% | Jan 29, 2026 | Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low pri... |
| CVE-2026-23571 | MEDIUM | 6.8 | 0.7% | Jan 29, 2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Run... |
| CVE-2026-23570 | MEDIUM | 6.5 | 0.7% | Jan 29, 2026 | A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution S... |
| CVE-2026-23567 | MEDIUM | 6.5 | 0.3% | Jan 29, 2026 | An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution S... |
| CVE-2026-23566 | MEDIUM | 6.5 | 0.2% | Jan 29, 2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2026-23565 | MEDIUM | 6.5 | 0.2% | Jan 29, 2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2026-23564 | MEDIUM | 6.5 | 0.1% | Jan 29, 2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2026-25067 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the bac... |
| CVE-2026-1549 | MEDIUM | 4.3 | 0.5% | Jan 28, 2026 | A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionalit... |
| CVE-2026-24889 | MEDIUM | 5.3 | 0.4% | Jan 28, 2026 | soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now