2026 CVE Vulnerabilities
56,354 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23743 | HIGH | 7.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permali... |
| CVE-2026-24775 | HIGH | 7.3 | 0.1% | Jan 28, 2026 | OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents base... |
| CVE-2026-0750 | HIGH | 7.5 | 0.3% | Jan 28, 2026 | Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupa... |
| CVE-2026-24685 | HIGH | 8.8 | 0.3% | Jan 28, 2026 | OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitr... |
| CVE-2026-22243 | HIGH | 8.8 | 0.4% | Jan 28, 2026 | EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components o... |
| CVE-2026-1522 | HIGH | 7.5 | 0.7% | Jan 28, 2026 | A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_be... |
| CVE-2026-1521 | HIGH | 7.5 | 0.5% | Jan 28, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_fa... |
| CVE-2026-1280 | HIGH | 7.5 | 0.3% | Jan 28, 2026 | The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability ch... |
| CVE-2026-0844 | HIGH | 8.8 | 0.3% | Jan 28, 2026 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including... |
| CVE-2026-1400 | HIGH | 7.2 | 0.7% | Jan 28, 2026 | The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2026-0702 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'f... |
| CVE-2026-0832 | HIGH | 7.3 | 0.3% | Jan 28, 2026 | The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a... |
| CVE-2026-1514 | HIGH | 7.1 | 0.3% | Jan 28, 2026 | Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing a... |
| CVE-2026-1506 | HIGH | 7.3 | 5.1% | Jan 28, 2026 | A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php o... |
| CVE-2026-1505 | HIGH | 7.3 | 4.5% | Jan 28, 2026 | A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes... |
| CVE-2026-24852 | HIGH | 8.1 | 0.2% | Jan 28, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-24842 | HIGH | 8.2 | 0.5% | Jan 28, 2026 | node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink en... |
| CVE-2026-24840 | HIGH | 8.8 | 0.3% | Jan 28, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in th... |
| CVE-2026-21569 | HIGH | 7.9 | 0.3% | Jan 28, 2026 | This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Cente... |
| CVE-2026-24783 | HIGH | 7.5 | 0.4% | Jan 27, 2026 | soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mul... |
| CVE-2026-24779 | HIGH | 7.1 | 0.5% | Jan 27, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request... |
| CVE-2026-24765 | HIGH | 7.8 | 0.3% | Jan 27, 2026 | PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.6... |
| CVE-2026-24748 | HIGH | 7.2 | 0.3% | Jan 27, 2026 | Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was fo... |
| CVE-2026-24747 | HIGH | 8.8 | 0.7% | Jan 27, 2026 | PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei... |
| CVE-2026-24741 | HIGH | 8.1 | 0.4% | Jan 27, 2026 | ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-con... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now