2026 CVE Vulnerabilities
56,336 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1117 | HIGH | 8.2 | 0.4% | Feb 2, 2026 | A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated a... |
| CVE-2026-20412 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2026-20411 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv... |
| CVE-2026-20409 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2026-20408 | HIGH | 8.8 | 0.3% | Feb 2, 2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja... |
| CVE-2026-20401 | HIGH | 7.5 | 0.7% | Feb 2, 2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if... |
| CVE-2026-22888 | HIGH | 7.5 | 0.4% | Feb 2, 2026 | Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of p... |
| CVE-2026-1746 | HIGH | 8.8 | 0.4% | Feb 2, 2026 | A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap... |
| CVE-2026-1531 | HIGH | 8.1 | 0.3% | Feb 2, 2026 | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification... |
| CVE-2026-1530 | HIGH | 8.1 | 0.3% | Feb 2, 2026 | A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) atta... |
| CVE-2026-25201 | HIGH | 8.8 | 0.4% | Feb 2, 2026 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9... |
| CVE-2026-24788 | HIGH | 8.8 | 1.3% | Feb 2, 2026 | RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary O... |
| CVE-2026-1742 | HIGH | 7.2 | 0.3% | Feb 2, 2026 | A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncl... |
| CVE-2026-1739 | HIGH | 7.5 | 0.7% | Feb 2, 2026 | A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the ... |
| CVE-2026-25253 | HIGH | 8.8 | 8.0% | Feb 1, 2026 | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak... |
| CVE-2026-23025 | HIGH | 7.8 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n T... |
| CVE-2026-25153 | HIGH | 8.8 | 0.5% | Jan 30, 2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.... |
| CVE-2026-25129 | HIGH | 7.3 | 0.3% | Jan 30, 2026 | PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, Psy... |
| CVE-2026-1702 | HIGH | 8.8 | 0.4% | Jan 30, 2026 | A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of ... |
| CVE-2026-1691 | HIGH | 8.8 | 0.5% | Jan 30, 2026 | A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/m... |
| CVE-2026-1689 | HIGH | 7.3 | 2.3% | Jan 30, 2026 | A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function che... |
| CVE-2026-25128 | HIGH | 7.5 | 0.6% | Jan 30, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-24854 | HIGH | 8.8 | 0.4% | Jan 30, 2026 | ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor... |
| CVE-2026-1687 | HIGH | 7.3 | 2.4% | Jan 30, 2026 | A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the... |
| CVE-2026-1686 | HIGH | 8.8 | 0.7% | Jan 30, 2026 | A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now