2026 CVE Vulnerabilities
53,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22242 | MEDIUM | 4.9 | 0.4% | Jan 8, 2026 | CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in... |
| CVE-2026-21894 | MEDIUM | 6.5 | 0.4% | Jan 8, 2026 | n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass v... |
| CVE-2026-21874 | MEDIUM | 5.3 | 0.5% | Jan 8, 2026 | NiceGUI is a Python-based UI framework. From versions v2.10.0 to 3.4.1, an unauthenticated attacker can exhaust Redis co... |
| CVE-2026-21873 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event l... |
| CVE-2026-21872 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event liste... |
| CVE-2026-21871 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | NiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pa... |
| CVE-2026-0676 | MEDIUM | 5.3 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-0674 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Con... |
| CVE-2026-0707 | MEDIUM | 5.3 | 0.4% | Jan 8, 2026 | A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of ... |
| CVE-2026-21883 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured ... |
| CVE-2026-21880 | MEDIUM | 5.3 | 0.4% | Jan 8, 2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection ... |
| CVE-2026-21879 | MEDIUM | 6.1 | 0.3% | Jan 8, 2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Op... |
| CVE-2026-21859 | MEDIUM | 5.3 | 0.8% | Jan 8, 2026 | Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S... |
| CVE-2026-21695 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnera... |
| CVE-2026-21857 | MEDIUM | 6.5 | 0.5% | Jan 7, 2026 | REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions ca... |
| CVE-2026-21851 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P... |
| CVE-2026-21691 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio... |
| CVE-2026-21690 | MEDIUM | 6.3 | 0.2% | Jan 7, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio... |
| CVE-2026-21689 | MEDIUM | 6.5 | 0.3% | Jan 7, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio... |
| CVE-2026-22188 | MEDIUM | 5.5 | 0.2% | Jan 7, 2026 | The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due... |
| CVE-2026-22185 | MEDIUM | 4.6 | 0.1% | Jan 7, 2026 | OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a... |
| CVE-2026-21855 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scrip... |
| CVE-2026-0670 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-22539 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could ob... |
| CVE-2026-21506 | MEDIUM | 5.5 | 0.2% | Jan 7, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now