2026 CVE Vulnerabilities
53,576 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24047 | MEDIUM | 6.3 | 0.4% | Jan 21, 2026 | Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functio... |
| CVE-2026-23990 | MEDIUM | 5.3 | 0.3% | Jan 21, 2026 | The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterpr... |
| CVE-2026-23968 | MEDIUM | 5.5 | 0.2% | Jan 21, 2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe... |
| CVE-2026-23630 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code blo... |
| CVE-2026-23960 | MEDIUM | 5.4 | 0.3% | Jan 21, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-23516 | MEDIUM | 5.4 | 0.1% | Jan 21, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0... |
| CVE-2026-23499 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor... |
| CVE-2026-22849 | MEDIUM | 4.8 | 0.2% | Jan 21, 2026 | Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor... |
| CVE-2026-22808 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, i... |
| CVE-2026-23955 | MEDIUM | 4.2 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated ... |
| CVE-2026-20109 | MEDIUM | 4.8 | 0.2% | Jan 21, 2026 | Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE... |
| CVE-2026-20092 | MEDIUM | 6 | 0.1% | Jan 21, 2026 | A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, l... |
| CVE-2026-20080 | MEDIUM | 5.3 | 0.3% | Jan 21, 2026 | A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticat... |
| CVE-2026-20055 | MEDIUM | 4.8 | 0.2% | Jan 21, 2026 | Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE... |
| CVE-2026-1290 | MEDIUM | 5.3 | 0.3% | Jan 21, 2026 | Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Ja... |
| CVE-2026-22977 | MEDIUM | 5.5 | 0.1% | Jan 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv... |
| CVE-2026-0663 | MEDIUM | 4.9 | 0.4% | Jan 21, 2026 | Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vau... |
| CVE-2026-22976 | MEDIUM | 5.5 | 0.1% | Jan 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivatin... |
| CVE-2026-21985 | MEDIUM | 6 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2026-21982 | MEDIUM | 6.4 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2026-21981 | MEDIUM | 4.6 | 0.1% | Jan 20, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2026-21980 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Plat... |
| CVE-2026-21979 | MEDIUM | 4.2 | 0.1% | Jan 20, 2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th... |
| CVE-2026-21978 | MEDIUM | 6.5 | 0.3% | Jan 20, 2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Rel... |
| CVE-2026-21975 | MEDIUM | 4.5 | 0.2% | Jan 20, 2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now