2026 CVE Vulnerabilities
53,599 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23493 | MEDIUM | 4.9 | 0.4% | Jan 15, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file st... |
| CVE-2026-22867 | MEDIUM | 5.4 | 0.3% | Jan 15, 2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Sc... |
| CVE-2026-20076 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2026-20075 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2026-20047 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden... |
| CVE-2026-0990 | MEDIUM | 5.9 | 0.8% | Jan 15, 2026 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogX... |
| CVE-2026-22645 | MEDIUM | 5.3 | 0.4% | Jan 15, 2026 | The application discloses all used components, versions and license information to unauthenticated actors, giving attack... |
| CVE-2026-22919 | MEDIUM | 4.8 | 0.3% | Jan 15, 2026 | An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site... |
| CVE-2026-22916 | MEDIUM | 5.4 | 0.3% | Jan 15, 2026 | An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without... |
| CVE-2026-22915 | MEDIUM | 6.5 | 0.4% | Jan 15, 2026 | An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing ... |
| CVE-2026-22914 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | An attacker with limited permissions may still be able to write files to specific locations on the device, potentially l... |
| CVE-2026-22913 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead ... |
| CVE-2026-22912 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authenticatio... |
| CVE-2026-0600 | MEDIUM | 6.2 | 0.3% | Jan 14, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenti... |
| CVE-2026-0601 | MEDIUM | 5.1 | 0.4% | Jan 14, 2026 | A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to exe... |
| CVE-2026-0962 | MEDIUM | 6.5 | 0.2% | Jan 14, 2026 | SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service |
| CVE-2026-0961 | MEDIUM | 6.5 | 0.2% | Jan 14, 2026 | BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service |
| CVE-2026-0960 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service |
| CVE-2026-0959 | MEDIUM | 6.5 | 0.2% | Jan 14, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service |
| CVE-2026-23497 | MEDIUM | 5.4 | 0.1% | Jan 14, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and ear... |
| CVE-2026-23492 | MEDIUM | 4.9 | 0.4% | Jan 14, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injectio... |
| CVE-2026-23477 | MEDIUM | 6.5 | 0.3% | Jan 14, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,... |
| CVE-2026-22851 | MEDIUM | 5.9 | 0.2% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dy... |
| CVE-2026-22787 | MEDIUM | 6.1 | 0.3% | Jan 14, 2026 | html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js cont... |
| CVE-2026-22779 | MEDIUM | 5.3 | 0.3% | Jan 14, 2026 | BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now