2026 CVE Vulnerabilities
53,410 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23888 | MEDIUM | 6.5 | 0.4% | Jan 26, 2026 | pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows mali... |
| CVE-2026-1445 | MEDIUM | 4.7 | 0.2% | Jan 26, 2026 | A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability... |
| CVE-2026-24439 | MEDIUM | 6.5 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Option... |
| CVE-2026-24437 | MEDIUM | 5.5 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content wi... |
| CVE-2026-24435 | MEDIUM | 6.5 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resour... |
| CVE-2026-24433 | MEDIUM | 5.4 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vul... |
| CVE-2026-24432 | MEDIUM | 4.3 | 0.1% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) pr... |
| CVE-2026-24431 | MEDIUM | 6.5 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in ... |
| CVE-2026-1446 | MEDIUM | 5 | 0.1% | Jan 26, 2026 | There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli... |
| CVE-2026-1224 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Discover. |
| CVE-2026-0925 | MEDIUM | 4.9 | 0.4% | Jan 26, 2026 | Tanium addressed an improper input validation vulnerability in Discover. |
| CVE-2026-1429 | MEDIUM | 5.4 | 0.2% | Jan 26, 2026 | Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authen... |
| CVE-2026-1425 | MEDIUM | 6.3 | 0.4% | Jan 26, 2026 | A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_r... |
| CVE-2026-1421 | MEDIUM | 5.4 | 0.3% | Jan 26, 2026 | A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the co... |
| CVE-2026-1411 | MEDIUM | 6.1 | 0.2% | Jan 26, 2026 | A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the co... |
| CVE-2026-1410 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the compone... |
| CVE-2026-1409 | MEDIUM | 4.2 | 0.3% | Jan 26, 2026 | A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown ... |
| CVE-2026-1408 | MEDIUM | 4.2 | 0.3% | Jan 25, 2026 | A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of t... |
| CVE-2026-1407 | MEDIUM | 4.2 | 0.3% | Jan 25, 2026 | A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the com... |
| CVE-2026-23011 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to... |
| CVE-2026-23009 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: xhci: sideband: don't dereference freed ring when r... |
| CVE-2026-23008 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW ve... |
| CVE-2026-23007 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer... |
| CVE-2026-23006 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: tlv320adcx140: fix null pointer The "snd_soc... |
| CVE-2026-23005 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now