2026 CVE Vulnerabilities
53,599 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22694 | MEDIUM | 6.1 | 0.1% | Jan 14, 2026 | AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through ... |
| CVE-2026-22211 | MEDIUM | 5.1 | 0.2% | Jan 14, 2026 | TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted out... |
| CVE-2026-22239 | MEDIUM | 5.3 | 0.3% | Jan 14, 2026 | The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker co... |
| CVE-2026-0529 | MEDIUM | 6.5 | 0.2% | Jan 14, 2026 | Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Over... |
| CVE-2026-0813 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'sh... |
| CVE-2026-0812 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'li... |
| CVE-2026-0741 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se... |
| CVE-2026-0739 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a... |
| CVE-2026-0734 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter... |
| CVE-2026-0717 | MEDIUM | 5.3 | 0.3% | Jan 14, 2026 | The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2026-0694 | MEDIUM | 6.4 | 0.2% | Jan 14, 2026 | The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all... |
| CVE-2026-0680 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a... |
| CVE-2026-0678 | MEDIUM | 4.9 | 0.3% | Jan 14, 2026 | The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c... |
| CVE-2026-0635 | MEDIUM | 4.3 | 0.2% | Jan 14, 2026 | The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2026-0594 | MEDIUM | 6.1 | 0.7% | Jan 14, 2026 | The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' paramete... |
| CVE-2026-22718 | MEDIUM | 6.8 | 0.5% | Jan 14, 2026 | The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users mac... |
| CVE-2026-0716 | MEDIUM | 4.8 | 0.3% | Jan 13, 2026 | A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration... |
| CVE-2026-21303 | MEDIUM | 5.5 | 0.2% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to... |
| CVE-2026-21302 | MEDIUM | 5.5 | 0.2% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to... |
| CVE-2026-21301 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le... |
| CVE-2026-21300 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le... |
| CVE-2026-0543 | MEDIUM | 6.5 | 0.4% | Jan 13, 2026 | Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (C... |
| CVE-2026-0531 | MEDIUM | 6.5 | 0.4% | Jan 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1... |
| CVE-2026-0530 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1... |
| CVE-2026-22818 | MEDIUM | 6.5 | 0.1% | Jan 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now