2026 CVE Vulnerabilities
53,439 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24140 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme... |
| CVE-2026-24139 | MEDIUM | 6.5 | 0.3% | Jan 24, 2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard aga... |
| CVE-2026-24128 | MEDIUM | 6.1 | 0.5% | Jan 24, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi... |
| CVE-2026-24127 | MEDIUM | 6.1 | 0.3% | Jan 23, 2026 | Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Sc... |
| CVE-2026-1386 | MEDIUM | 6 | 0.2% | Jan 23, 2026 | A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on L... |
| CVE-2026-1299 | MEDIUM | 6 | 0.6% | Jan 23, 2026 | The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when seria... |
| CVE-2026-22994 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_... |
| CVE-2026-22993 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL ptr issue after soft reset ... |
| CVE-2026-22992 | MEDIUM | 5.5 | 0.3% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_a... |
| CVE-2026-22991 | MEDIUM | 5.5 | 0.4% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to pa... |
| CVE-2026-22990 | MEDIUM | 5.5 | 0.3% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply... |
| CVE-2026-22989 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: check that server is running in unlock_filesy... |
| CVE-2026-22988 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not chang... |
| CVE-2026-22987 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: avoid dereferencing ERR_PTR in ... |
| CVE-2026-22986 | MEDIUM | 4.7 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two ... |
| CVE-2026-22985 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL pointer crash on early ethto... |
| CVE-2026-22983 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: do not write to msg_get_inq in callee NULL po... |
| CVE-2026-22982 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface ... |
| CVE-2026-22981 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: detach and close netdevs while handling a res... |
| CVE-2026-22979 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO pa... |
| CVE-2026-24636 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrect... |
| CVE-2026-24634 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Ex... |
| CVE-2026-24633 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allo... |
| CVE-2026-24632 | MEDIUM | 5.9 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay R... |
| CVE-2026-24631 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now