2026 CVE Vulnerabilities
56,354 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24869 | HIGH | 8.8 | 0.2% | Jan 27, 2026 | Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2. |
| CVE-2026-24831 | HIGH | 7.5 | 0.3% | Jan 27, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ix... |
| CVE-2026-24828 | HIGH | 7.5 | 0.3% | Jan 27, 2026 | Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: be... |
| CVE-2026-24827 | HIGH | 7.5 | 0.3% | Jan 27, 2026 | Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs... |
| CVE-2026-24345 | HIGH | 8.8 | 0.1% | Jan 27, 2026 | Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization che... |
| CVE-2026-21417 | HIGH | 7.2 | 0.2% | Jan 27, 2026 | Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability. ... |
| CVE-2026-24817 | HIGH | 8.7 | 0.3% | Jan 27, 2026 | Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with ... |
| CVE-2026-24813 | HIGH | 8.7 | 0.3% | Jan 27, 2026 | NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerabilit... |
| CVE-2026-24808 | HIGH | 8.3 | 0.1% | Jan 27, 2026 | Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with pr... |
| CVE-2026-24344 | HIGH | 7.3 | 0.2% | Jan 27, 2026 | Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and ... |
| CVE-2026-21721 | HIGH | 8.1 | 0.6% | Jan 27, 2026 | The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac... |
| CVE-2026-21720 | HIGH | 7.5 | 0.6% | Jan 27, 2026 | Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10... |
| CVE-2026-1465 | HIGH | 8.7 | 0.1% | Jan 27, 2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in anyrtcIO-Community anyRTC-RTMP-... |
| CVE-2026-21408 | HIGH | 7.3 | 0.1% | Jan 27, 2026 | beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely... |
| CVE-2026-24486 | HIGH | 7.5 | 2.2% | Jan 27, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exi... |
| CVE-2026-24480 | HIGH | 8.7 | 0.4% | Jan 27, 2026 | QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actio... |
| CVE-2026-24478 | HIGH | 7.2 | 0.9% | Jan 27, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-24477 | HIGH | 7.5 | 1.6% | Jan 27, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-1449 | HIGH | 7.3 | 0.4% | Jan 27, 2026 | A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Loa... |
| CVE-2026-1448 | HIGH | 7.3 | 5.3% | Jan 27, 2026 | A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_ma... |
| CVE-2026-24470 | HIGH | 8.1 | 0.3% | Jan 26, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an... |
| CVE-2026-23864 | HIGH | 7.5 | 2.5% | Jan 26, 2026 | Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser... |
| CVE-2026-0810 | HIGH | 7.1 | 0.2% | Jan 26, 2026 | A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid no... |
| CVE-2026-24440 | HIGH | 8.8 | 0.3% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed thr... |
| CVE-2026-24430 | HIGH | 7.5 | 0.2% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now