2026 CVE Vulnerabilities
56,336 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1498 | HIGH | 7 | 0.7% | Jan 30, 2026 | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensit... |
| CVE-2026-22623 | HIGH | 7.2 | 0.5% | Jan 30, 2026 | Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can... |
| CVE-2026-0709 | HIGH | 7.2 | 0.8% | Jan 30, 2026 | Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input valida... |
| CVE-2026-1699 | HIGH | 8.8 | 0.5% | Jan 30, 2026 | In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar... |
| CVE-2026-22277 | HIGH | 7.8 | 0.6% | Jan 30, 2026 | Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command... |
| CVE-2026-21418 | HIGH | 7.8 | 0.6% | Jan 30, 2026 | Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ... |
| CVE-2026-25210 | HIGH | 7.8 | 0.2% | Jan 30, 2026 | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no... |
| CVE-2026-1680 | HIGH | 7.8 | 0.2% | Jan 30, 2026 | Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Win... |
| CVE-2026-0963 | HIGH | 8.8 | 0.7% | Jan 30, 2026 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote... |
| CVE-2026-0805 | HIGH | 8.8 | 0.6% | Jan 30, 2026 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authen... |
| CVE-2026-24714 | HIGH | 8.7 | 0.2% | Jan 30, 2026 | Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telne... |
| CVE-2026-1638 | HIGH | 8.8 | 1.8% | Jan 30, 2026 | A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZ... |
| CVE-2026-1637 | HIGH | 8.8 | 0.6% | Jan 29, 2026 | A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of th... |
| CVE-2026-25126 | HIGH | 7.1 | 0.3% | Jan 29, 2026 | PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/... |
| CVE-2026-25117 | HIGH | 8.3 | 0.6% | Jan 29, 2026 | pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6... |
| CVE-2026-25116 | HIGH | 8.8 | 0.6% | Jan 29, 2026 | Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated ... |
| CVE-2026-25063 | HIGH | 7.8 | 0.7% | Jan 29, 2026 | gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gr... |
| CVE-2026-25061 | HIGH | 7.5 | 0.5% | Jan 29, 2026 | tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame ... |
| CVE-2026-25047 | HIGH | 8.8 | 0.7% | Jan 29, 2026 | deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution ... |
| CVE-2026-25040 | HIGH | 8.8 | 0.5% | Jan 29, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin... |
| CVE-2026-24905 | HIGH | 7.8 | 1.3% | Jan 29, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-24902 | HIGH | 7.1 | 0.2% | Jan 29, 2026 | TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass... |
| CVE-2026-1625 | HIGH | 8.8 | 2.3% | Jan 29, 2026 | A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boa... |
| CVE-2026-1624 | HIGH | 8.8 | 2.3% | Jan 29, 2026 | A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the... |
| CVE-2026-1610 | HIGH | 8.1 | 0.7% | Jan 29, 2026 | A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now