2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1225 | LOW | 1.8 | 0.2% | Jan 22, 2026 | ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java ap... |
| CVE-2026-24048 | LOW | 3.7 | 0.2% | Jan 21, 2026 | Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl... |
| CVE-2026-23996 | LOW | 3.7 | 0.3% | Jan 21, 2026 | FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-cha... |
| CVE-2026-0988 | LOW | 3.7 | 0.4% | Jan 21, 2026 | A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() functi... |
| CVE-2026-1035 | LOW | 3.1 | 0.3% | Jan 21, 2026 | A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi... |
| CVE-2026-21977 | LOW | 3.1 | 0.2% | Jan 20, 2026 | Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Applian... |
| CVE-2026-21965 | LOW | 2.7 | 0.3% | Jan 20, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that ... |
| CVE-2026-21947 | LOW | 3.1 | 0.2% | Jan 20, 2026 | Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50... |
| CVE-2026-21930 | LOW | 2.3 | 0.1% | Jan 20, 2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte... |
| CVE-2026-21640 | LOW | 2.7 | 0.2% | Jan 20, 2026 | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti... |
| CVE-2026-1197 | LOW | 3.1 | 0.3% | Jan 20, 2026 | A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the fil... |
| CVE-2026-23522 | LOW | 3.7 | 0.2% | Jan 19, 2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno... |
| CVE-2026-1161 | LOW | 3.5 | 0.2% | Jan 19, 2026 | A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil... |
| CVE-2026-1136 | LOW | 3.5 | 0.2% | Jan 19, 2026 | A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio... |
| CVE-2026-0682 | LOW | 2.2 | 0.2% | Jan 17, 2026 | The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,... |
| CVE-2026-0519 | LOW | 3.4 | 0.1% | Jan 17, 2026 | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u... |
| CVE-2026-0992 | LOW | 2.9 | 0.4% | Jan 15, 2026 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML... |
| CVE-2026-0989 | LOW | 3.7 | 0.5% | Jan 15, 2026 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser... |
| CVE-2026-0976 | LOW | 3.7 | 0.4% | Jan 15, 2026 | A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant... |
| CVE-2026-22819 | LOW | 3.1 | 0.2% | Jan 14, 2026 | Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more t... |
| CVE-2026-22820 | LOW | 3.7 | 0.2% | Jan 14, 2026 | Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the s... |
| CVE-2026-0510 | LOW | 3 | 0.1% | Jan 13, 2026 | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi... |
| CVE-2026-0504 | LOW | 3.8 | 0.2% | Jan 13, 2026 | Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to ... |
| CVE-2026-0824 | LOW | 3.5 | 0.2% | Jan 10, 2026 | A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con... |
| CVE-2026-22611 | LOW | 3.7 | 0.2% | Jan 10, 2026 | AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now