2026 CVE Vulnerabilities
53,410 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24819 | MEDIUM | 6.3 | 0.4% | Jan 27, 2026 | Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/fo... |
| CVE-2026-24818 | MEDIUM | 6.9 | 0.4% | Jan 27, 2026 | Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with p... |
| CVE-2026-24809 | MEDIUM | 6.9 | 0.1% | Jan 27, 2026 | An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 l... |
| CVE-2026-24807 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-f... |
| CVE-2026-24806 | MEDIUM | 5.3 | 0.4% | Jan 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/bati... |
| CVE-2026-24805 | MEDIUM | 6.7 | 0.1% | Jan 27, 2026 | NULL Pointer Dereference vulnerability in visualfc liteide (liteidex/src/3rdparty/libvterm/src modules). This vulnerabil... |
| CVE-2026-24802 | MEDIUM | 5.3 | 0.4% | Jan 27, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlec... |
| CVE-2026-24801 | MEDIUM | 6.9 | 0.2% | Jan 27, 2026 | Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source mod... |
| CVE-2026-24799 | MEDIUM | 5.2 | 0.1% | Jan 27, 2026 | Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking d... |
| CVE-2026-24797 | MEDIUM | 6.9 | 0.3% | Jan 27, 2026 | Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerabili... |
| CVE-2026-24796 | MEDIUM | 6.9 | 0.1% | Jan 27, 2026 | Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onigu... |
| CVE-2026-24795 | MEDIUM | 5.1 | 0.1% | Jan 27, 2026 | Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onig... |
| CVE-2026-1464 | MEDIUM | 4.6 | 0.1% | Jan 27, 2026 | Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/... |
| CVE-2026-24686 | MEDIUM | 4.7 | 0.2% | Jan 27, 2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repositor... |
| CVE-2026-24490 | MEDIUM | 4.8 | 0.3% | Jan 27, 2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vu... |
| CVE-2026-24489 | MEDIUM | 5.3 | 0.4% | Jan 27, 2026 | Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in ... |
| CVE-2026-23683 | MEDIUM | 4.3 | 0.2% | Jan 27, 2026 | SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u... |
| CVE-2026-24476 | MEDIUM | 5.4 | 0.1% | Jan 26, 2026 | Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` pre... |
| CVE-2026-24408 | MEDIUM | 5 | 0.2% | Jan 26, 2026 | sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-... |
| CVE-2026-24123 | MEDIUM | 6.5 | 0.4% | Jan 26, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to vers... |
| CVE-2026-24131 | MEDIUM | 5.5 | 0.2% | Jan 26, 2026 | pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `p... |
| CVE-2026-24056 | MEDIUM | 6.5 | 0.5% | Jan 26, 2026 | pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it f... |
| CVE-2026-24003 | MEDIUM | 5.3 | 0.3% | Jan 26, 2026 | EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen... |
| CVE-2026-23890 | MEDIUM | 6.5 | 0.4% | Jan 26, 2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicio... |
| CVE-2026-23889 | MEDIUM | 6.5 | 0.4% | Jan 26, 2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now