2026 CVE Vulnerabilities
53,578 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21934 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Push Notifications). Su... |
| CVE-2026-21933 | MEDIUM | 6.1 | 0.3% | Jan 20, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-21931 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Support... |
| CVE-2026-21929 | MEDIUM | 5.3 | 0.3% | Jan 20, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe... |
| CVE-2026-21928 | MEDIUM | 5.3 | 0.3% | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec... |
| CVE-2026-21927 | MEDIUM | 5.8 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec... |
| CVE-2026-21925 | MEDIUM | 4.8 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-21924 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General... |
| CVE-2026-21923 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Pl... |
| CVE-2026-21922 | MEDIUM | 4.2 | 0.1% | Jan 20, 2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th... |
| CVE-2026-0865 | MEDIUM | 5.9 | 0.5% | Jan 20, 2026 | User-controlled header names and values containing newlines can allow injecting HTTP headers. |
| CVE-2026-0672 | MEDIUM | 6 | 0.4% | Jan 20, 2026 | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messa... |
| CVE-2026-21664 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php de... |
| CVE-2026-21663 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of... |
| CVE-2026-21642 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `ch... |
| CVE-2026-21641 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-dele... |
| CVE-2026-0622 | MEDIUM | 6.5 | 0.4% | Jan 20, 2026 | Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset |
| CVE-2026-1245 | MEDIUM | 6.5 | 0.5% | Jan 20, 2026 | A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code exec... |
| CVE-2026-0690 | MEDIUM | 6.4 | 0.2% | Jan 20, 2026 | The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2026-0608 | MEDIUM | 6.4 | 0.2% | Jan 20, 2026 | The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta ... |
| CVE-2026-0554 | MEDIUM | 4.3 | 0.3% | Jan 20, 2026 | The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2026-0548 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment delet... |
| CVE-2026-1183 | MEDIUM | 5.1 | 0.3% | Jan 20, 2026 | HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an ... |
| CVE-2026-1180 | MEDIUM | 5.8 | 0.4% | Jan 20, 2026 | A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p... |
| CVE-2026-0895 | MEDIUM | 5.2 | 0.1% | Jan 20, 2026 | The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now