2026 CVE Vulnerabilities
53,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22253 | MEDIUM | 5.4 | 0.3% | Jan 8, 2026 | Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the L... |
| CVE-2026-21860 | MEDIUM | 5.3 | 0.4% | Jan 8, 2026 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows p... |
| CVE-2026-22587 | MEDIUM | 5.5 | 0.2% | Jan 8, 2026 | Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a pa... |
| CVE-2026-22233 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field... |
| CVE-2026-22232 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project... |
| CVE-2026-22231 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functi... |
| CVE-2026-21896 | MEDIUM | 5.7 | 0.2% | Jan 8, 2026 | Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in t... |
| CVE-2026-22522 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-22519 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPres... |
| CVE-2026-22518 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons ... |
| CVE-2026-22517 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiti... |
| CVE-2026-22492 | MEDIUM | 4.3 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured ... |
| CVE-2026-22490 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Ex... |
| CVE-2026-22489 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slidesho... |
| CVE-2026-22488 | MEDIUM | 5.3 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beav... |
| CVE-2026-22487 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in baqend Speed Kit baqend allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-22486 | MEDIUM | 5.3 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Level... |
| CVE-2026-0671 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-22246 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed ... |
| CVE-2026-22041 | MEDIUM | 5.3 | 0.2% | Jan 8, 2026 | Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictiona... |
| CVE-2026-22032 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redir... |
| CVE-2026-22028 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from bein... |
| CVE-2026-21895 | MEDIUM | 5.3 | 0.4% | Jan 8, 2026 | The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from ... |
| CVE-2026-21885 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encoded... |
| CVE-2026-21876 | MEDIUM | 5.3 | 13.1% | Jan 8, 2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now