2026 CVE Vulnerabilities
53,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0831 | MEDIUM | 5.3 | 0.2% | Jan 10, 2026 | The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. T... |
| CVE-2026-22705 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryp... |
| CVE-2026-22704 | MEDIUM | 5.4 | 1.0% | Jan 10, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vul... |
| CVE-2026-22703 | MEDIUM | 5.5 | 0.1% | Jan 10, 2026 | Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bun... |
| CVE-2026-22702 | MEDIUM | 4.5 | 0.1% | Jan 10, 2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-... |
| CVE-2026-22701 | MEDIUM | 5.3 | 0.1% | Jan 10, 2026 | filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability ... |
| CVE-2026-22693 | MEDIUM | 5.3 | 0.4% | Jan 10, 2026 | HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the Subta... |
| CVE-2026-22689 | MEDIUM | 6.5 | 0.2% | Jan 10, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is config... |
| CVE-2026-22691 | MEDIUM | 5.3 | 0.4% | Jan 10, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for ma... |
| CVE-2026-22690 | MEDIUM | 5.3 | 0.4% | Jan 10, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for mi... |
| CVE-2026-22610 | MEDIUM | 6.1 | 0.4% | Jan 10, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-22030 | MEDIUM | 6.5 | 0.1% | Jan 10, 2026 | React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through... |
| CVE-2026-22029 | MEDIUM | 6.1 | 0.8% | Jan 10, 2026 | React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, ... |
| CVE-2026-22605 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allo... |
| CVE-2026-22604 | MEDIUM | 5.3 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.... |
| CVE-2026-22603 | MEDIUM | 6.5 | 0.2% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthentic... |
| CVE-2026-22027 | MEDIUM | 6 | 0.2% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22024 | MEDIUM | 5.3 | 0.4% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21900 | MEDIUM | 5.9 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21899 | MEDIUM | 4.9 | 0.3% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22198 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API... |
| CVE-2026-0817 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.... |
| CVE-2026-0627 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up... |
| CVE-2026-20975 | MEDIUM | 5.5 | 0.1% | Jan 9, 2026 | Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access s... |
| CVE-2026-20974 | MEDIUM | 4.6 | 0.2% | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now