2026 CVE Vulnerabilities
53,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24883 | MEDIUM | 5.5 | 0.4% | Jan 27, 2026 | In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to ... |
| CVE-2026-24398 | MEDIUM | 6.5 | 0.3% | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restri... |
| CVE-2026-24116 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x8... |
| CVE-2026-23892 | MEDIUM | 5.9 | 0.5% | Jan 27, 2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 a... |
| CVE-2026-22263 | MEDIUM | 5.3 | 0.4% | Jan 27, 2026 | Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in htt... |
| CVE-2026-22261 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handlin... |
| CVE-2026-0746 | MEDIUM | 6.4 | 0.2% | Jan 27, 2026 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.... |
| CVE-2026-23881 | MEDIUM | 6.5 | 0.5% | Jan 27, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav... |
| CVE-2026-0705 | MEDIUM | 6.7 | 0.1% | Jan 27, 2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage... |
| CVE-2026-24868 | MEDIUM | 6.5 | 0.2% | Jan 27, 2026 | Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2. |
| CVE-2026-22796 | MEDIUM | 5.3 | 0.5% | Jan 27, 2026 | Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_T... |
| CVE-2026-22795 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. ... |
| CVE-2026-0648 | MEDIUM | 6.3 | 0.1% | Jan 27, 2026 | The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_... |
| CVE-2026-1489 | MEDIUM | 5.4 | 0.3% | Jan 27, 2026 | A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to me... |
| CVE-2026-1484 | MEDIUM | 4.2 | 0.3% | Jan 27, 2026 | A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of inte... |
| CVE-2026-1213 | MEDIUM | 4.3 | 0.3% | Jan 27, 2026 | All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modif... |
| CVE-2026-24829 | MEDIUM | 6.5 | 0.2% | Jan 27, 2026 | Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: befor... |
| CVE-2026-24348 | MEDIUM | 6.1 | 0.1% | Jan 27, 2026 | Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execut... |
| CVE-2026-24347 | MEDIUM | 5.3 | 0.2% | Jan 27, 2026 | Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /... |
| CVE-2026-1467 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec... |
| CVE-2026-24825 | MEDIUM | 6.9 | 0.3% | Jan 27, 2026 | Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This v... |
| CVE-2026-24824 | MEDIUM | 6.9 | 0.3% | Jan 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in yacy yacy_s... |
| CVE-2026-24820 | MEDIUM | 5.1 | 0.1% | Jan 27, 2026 | Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated... |
| CVE-2026-24819 | MEDIUM | 6.3 | 0.4% | Jan 27, 2026 | Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/fo... |
| CVE-2026-24818 | MEDIUM | 6.9 | 0.4% | Jan 27, 2026 | Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now