2026 CVE Vulnerabilities
53,576 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22360 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This ... |
| CVE-2026-22359 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross S... |
| CVE-2026-22358 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician... |
| CVE-2026-22353 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winkm89 teachPress... |
| CVE-2026-22349 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in linux4me2 Menu In ... |
| CVE-2026-22348 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Tasos Fel Civic Cookie Control civic-cookie-control-8 allows Exploiting Incorrect... |
| CVE-2026-22347 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in subhansanjaya Caro... |
| CVE-2026-1332 | MEDIUM | 6.9 | 0.4% | Jan 22, 2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote ... |
| CVE-2026-24332 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual... |
| CVE-2026-24049 | MEDIUM | 5.5 | 0.3% | Jan 22, 2026 | wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46... |
| CVE-2026-24055 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/sla... |
| CVE-2026-24039 | MEDIUM | 4.3 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, al... |
| CVE-2026-24037 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function atte... |
| CVE-2026-24036 | MEDIUM | 5.3 | 0.5% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished j... |
| CVE-2026-24035 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis... |
| CVE-2026-24034 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scri... |
| CVE-2026-23964 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,... |
| CVE-2026-23963 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,... |
| CVE-2026-23959 | MEDIUM | 4.9 | 0.4% | Jan 22, 2026 | CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions... |
| CVE-2026-23961 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to sus... |
| CVE-2026-23951 | MEDIUM | 5.5 | 0.2% | Jan 22, 2026 | SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that on... |
| CVE-2026-23946 | MEDIUM | 6.8 | 0.7% | Jan 22, 2026 | Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions... |
| CVE-2026-23893 | MEDIUM | 6.8 | 0.2% | Jan 22, 2026 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to sym... |
| CVE-2026-23887 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25... |
| CVE-2026-1036 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modificati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now