2026 CVE Vulnerabilities
53,578 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1223 | MEDIUM | 6.9 | 0.4% | Jan 20, 2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,... |
| CVE-2026-1218 | MEDIUM | 6.3 | 0.2% | Jan 20, 2026 | A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClient... |
| CVE-2026-1045 | MEDIUM | 4.4 | 0.2% | Jan 20, 2026 | The Viet contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-1042 | MEDIUM | 4.4 | 0.2% | Jan 20, 2026 | The WP Hello Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'digit_one' and 'digit_two' p... |
| CVE-2026-0904 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perfor... |
| CVE-2026-0903 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t... |
| CVE-2026-0901 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to pe... |
| CVE-2026-1051 | MEDIUM | 4.3 | 0.1% | Jan 20, 2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in ... |
| CVE-2026-23950 | MEDIUM | 5.9 | 0.2% | Jan 20, 2026 | node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an ... |
| CVE-2026-23874 | MEDIUM | 5.5 | 0.2% | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-1... |
| CVE-2026-1196 | MEDIUM | 5.3 | 0.4% | Jan 20, 2026 | A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/get... |
| CVE-2026-22218 | MEDIUM | 6.5 | 8.8% | Jan 20, 2026 | Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An au... |
| CVE-2026-23886 | MEDIUM | 5.3 | 0.4% | Jan 19, 2026 | Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry P... |
| CVE-2026-23877 | MEDIUM | 4.3 | 0.5% | Jan 19, 2026 | Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` ... |
| CVE-2026-23875 | MEDIUM | 5.4 | 0.2% | Jan 19, 2026 | CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prio... |
| CVE-2026-23849 | MEDIUM | 5.3 | 0.4% | Jan 19, 2026 | File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview,... |
| CVE-2026-23848 | MEDIUM | 5.3 | 0.3% | Jan 19, 2026 | MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypas... |
| CVE-2026-23844 | MEDIUM | 4.3 | 0.2% | Jan 19, 2026 | Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulner... |
| CVE-2026-23851 | MEDIUM | 6.5 | 0.4% | Jan 19, 2026 | SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file... |
| CVE-2026-23847 | MEDIUM | 6.1 | 0.3% | Jan 19, 2026 | SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripti... |
| CVE-2026-21696 | MEDIUM | 6.5 | 0.5% | Jan 19, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version... |
| CVE-2026-23878 | MEDIUM | 6.5 | 0.3% | Jan 19, 2026 | HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ce... |
| CVE-2026-23841 | MEDIUM | 6.1 | 0.2% | Jan 19, 2026 | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a... |
| CVE-2026-23840 | MEDIUM | 6.1 | 0.2% | Jan 19, 2026 | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a... |
| CVE-2026-23839 | MEDIUM | 6.1 | 0.3% | Jan 19, 2026 | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now