2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1743 | LOW | 3.1 | 0.4% | Feb 2, 2026 | A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit... |
| CVE-2026-1705 | LOW | 2.4 | 0.2% | Jan 30, 2026 | A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_se... |
| CVE-2026-25211 | LOW | 3.2 | 0.2% | Jan 30, 2026 | Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. |
| CVE-2026-25046 | LOW | 2.9 | 0.1% | Jan 29, 2026 | Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publis... |
| CVE-2026-1588 | LOW | 2.7 | 0.6% | Jan 29, 2026 | A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshE... |
| CVE-2026-23553 | LOW | 2.9 | 0.1% | Jan 28, 2026 | In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the pr... |
| CVE-2026-1520 | LOW | 2.4 | 0.2% | Jan 28, 2026 | A vulnerability was identified in rethinkdb up to 2.4.3. Affected by this issue is some unknown functionality of the com... |
| CVE-2026-1237 | LOW | 2.1 | 0.1% | Jan 28, 2026 | Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us... |
| CVE-2026-1485 | LOW | 2.8 | 0.1% | Jan 27, 2026 | A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of ... |
| CVE-2026-1444 | LOW | 2.4 | 0.2% | Jan 26, 2026 | A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects ... |
| CVE-2026-1190 | LOW | 3.1 | 0.4% | Jan 26, 2026 | A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Asser... |
| CVE-2026-24656 | LOW | 3.7 | 0.7% | Jan 26, 2026 | Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes th... |
| CVE-2026-1417 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file app... |
| CVE-2026-1416 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of... |
| CVE-2026-1415 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file... |
| CVE-2026-1406 | LOW | 3.5 | 0.2% | Jan 25, 2026 | A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulner... |
| CVE-2026-0633 | LOW | 3.7 | 0.2% | Jan 24, 2026 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens... |
| CVE-2026-22978 | LOW | 3.3 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point s... |
| CVE-2026-24515 | LOW | 2.5 | 0.2% | Jan 23, 2026 | In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. |
| CVE-2026-0798 | LOW | 3.5 | 0.2% | Jan 22, 2026 | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos... |
| CVE-2026-22411 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr... |
| CVE-2026-22409 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco... |
| CVE-2026-22407 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly ... |
| CVE-2026-22406 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr... |
| CVE-2026-22404 | LOW | 3.8 | 0.2% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now