2026 CVE Vulnerabilities
53,539 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22398 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fleur fleur allows Exploiting Incorrectl... |
| CVE-2026-22396 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Inco... |
| CVE-2026-22393 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectl... |
| CVE-2026-22391 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Cocco cocco allows Exploiting Incorrectl... |
| CVE-2026-22388 | MEDIUM | 5.9 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu Owl Caro... |
| CVE-2026-22382 | MEDIUM | 5.4 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pa... |
| CVE-2026-22360 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This ... |
| CVE-2026-22359 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross S... |
| CVE-2026-22358 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician... |
| CVE-2026-22353 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winkm89 teachPress... |
| CVE-2026-22349 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linux4me2 Menu In ... |
| CVE-2026-22348 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Tasos Fel Civic Cookie Control civic-cookie-control-8 allows Exploiting Incorrect... |
| CVE-2026-22347 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in subhansanjaya Caro... |
| CVE-2026-1332 | MEDIUM | 6.9 | 0.4% | Jan 22, 2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote ... |
| CVE-2026-24332 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual... |
| CVE-2026-24049 | MEDIUM | 5.5 | 0.3% | Jan 22, 2026 | wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46... |
| CVE-2026-24055 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/sla... |
| CVE-2026-24039 | MEDIUM | 4.3 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, al... |
| CVE-2026-24037 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function atte... |
| CVE-2026-24036 | MEDIUM | 5.3 | 0.5% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished j... |
| CVE-2026-24035 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis... |
| CVE-2026-24034 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scri... |
| CVE-2026-23964 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,... |
| CVE-2026-23963 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,... |
| CVE-2026-23959 | MEDIUM | 4.9 | 0.4% | Jan 22, 2026 | CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now