2026 CVE Vulnerabilities
53,401 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24768 | MEDIUM | 6.1 | 0.3% | Jan 28, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redir... |
| CVE-2026-24767 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery... |
| CVE-2026-24766 | MEDIUM | 4.9 | 0.3% | Jan 28, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-leve... |
| CVE-2026-24742 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm... |
| CVE-2026-24739 | MEDIUM | 6.3 | 0.2% | Jan 28, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.... |
| CVE-2026-1532 | MEDIUM | 5.5 | 0.7% | Jan 28, 2026 | A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file ... |
| CVE-2026-21865 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat... |
| CVE-2026-0749 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builde... |
| CVE-2026-1539 | MEDIUM | 5.8 | 0.2% | Jan 28, 2026 | A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended de... |
| CVE-2026-1536 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C... |
| CVE-2026-23014 | MEDIUM | 5.5 | 0.1% | Jan 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed ... |
| CVE-2026-1060 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2026-1399 | MEDIUM | 4.4 | 0.2% | Jan 28, 2026 | The WP Google Ad Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ... |
| CVE-2026-1398 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2026-1391 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a... |
| CVE-2026-1380 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The Bitcoin Donate Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-1377 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The imwptip plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. ... |
| CVE-2026-0483 | MEDIUM | 6.9 | 0.2% | Jan 28, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior... |
| CVE-2026-1381 | MEDIUM | 4.4 | 0.3% | Jan 28, 2026 | The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-1053 | MEDIUM | 4.4 | 0.3% | Jan 28, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s... |
| CVE-2026-1389 | MEDIUM | 4.3 | 0.2% | Jan 28, 2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct O... |
| CVE-2026-1054 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.... |
| CVE-2026-0818 | MEDIUM | 4.3 | 0.2% | Jan 28, 2026 | When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of... |
| CVE-2026-1466 | MEDIUM | 6.1 | 0.3% | Jan 28, 2026 | Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents... |
| CVE-2026-1310 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now