2026 CVE Vulnerabilities
53,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22030 | MEDIUM | 6.5 | 0.1% | Jan 10, 2026 | React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through... |
| CVE-2026-22029 | MEDIUM | 6.1 | 0.8% | Jan 10, 2026 | React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, ... |
| CVE-2026-22605 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allo... |
| CVE-2026-22604 | MEDIUM | 5.3 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.... |
| CVE-2026-22603 | MEDIUM | 6.5 | 0.2% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthentic... |
| CVE-2026-22027 | MEDIUM | 6 | 0.2% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22024 | MEDIUM | 5.3 | 0.4% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21900 | MEDIUM | 5.9 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21899 | MEDIUM | 4.9 | 0.3% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22198 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API... |
| CVE-2026-0817 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.... |
| CVE-2026-0627 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up... |
| CVE-2026-20975 | MEDIUM | 5.5 | 0.1% | Jan 9, 2026 | Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access s... |
| CVE-2026-20974 | MEDIUM | 4.6 | 0.2% | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attack... |
| CVE-2026-20969 | MEDIUM | 5.5 | 0.2% | Jan 9, 2026 | Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with syste... |
| CVE-2026-20968 | MEDIUM | 6.7 | 0.2% | Jan 9, 2026 | Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code. |
| CVE-2026-0563 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Store... |
| CVE-2026-22713 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2026-22712 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia ... |
| CVE-2026-22710 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2026-0730 | MEDIUM | 4.8 | 0.2% | Jan 8, 2026 | A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UP... |
| CVE-2026-22588 | MEDIUM | 6.5 | 0.4% | Jan 8, 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5,... |
| CVE-2026-22253 | MEDIUM | 5.4 | 0.3% | Jan 8, 2026 | Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the L... |
| CVE-2026-21860 | MEDIUM | 5.3 | 0.4% | Jan 8, 2026 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows p... |
| CVE-2026-22587 | MEDIUM | 5.5 | 0.2% | Jan 8, 2026 | Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a pa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now