2026 CVE Vulnerabilities
56,354 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24428 | HIGH | 8.8 | 0.3% | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user... |
| CVE-2026-21509 | HIGH | 7.8 | 72.2% | Jan 26, 2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a secu... |
| CVE-2026-1284 | HIGH | 7.8 | 0.3% | Jan 26, 2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLI... |
| CVE-2026-1283 | HIGH | 7.8 | 0.2% | Jan 26, 2026 | A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Releas... |
| CVE-2026-1428 | HIGH | 8.8 | 1.3% | Jan 26, 2026 | Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re... |
| CVE-2026-1427 | HIGH | 8.8 | 1.3% | Jan 26, 2026 | Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re... |
| CVE-2026-1424 | HIGH | 7.2 | 0.4% | Jan 26, 2026 | A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic ... |
| CVE-2026-1419 | HIGH | 7.2 | 15.1% | Jan 26, 2026 | A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode o... |
| CVE-2026-1418 | HIGH | 7.8 | 0.2% | Jan 26, 2026 | A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the... |
| CVE-2026-23013 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in ... |
| CVE-2026-23012 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive cont... |
| CVE-2026-23010 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb... |
| CVE-2026-23001 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source... |
| CVE-2026-22998 | HIGH | 7.5 | 0.7% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tc... |
| CVE-2026-0911 | HIGH | 7.5 | 0.5% | Jan 24, 2026 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploa... |
| CVE-2026-0800 | HIGH | 7.2 | 0.2% | Jan 24, 2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-1257 | HIGH | 7.5 | 0.7% | Jan 24, 2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl... |
| CVE-2026-0807 | HIGH | 7.2 | 0.3% | Jan 24, 2026 | The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2026-24469 | HIGH | 7.5 | 0.6% | Jan 24, 2026 | C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below... |
| CVE-2026-24422 | HIGH | 7.5 | 0.4% | Jan 24, 2026 | phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly e... |
| CVE-2026-24412 | HIGH | 8.8 | 0.5% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24411 | HIGH | 8.8 | 0.3% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24410 | HIGH | 8.8 | 0.3% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24409 | HIGH | 8.8 | 0.3% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24407 | HIGH | 8.8 | 0.4% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now