2026 CVE Vulnerabilities
56,359 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24407 | HIGH | 8.8 | 0.4% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24406 | HIGH | 8.8 | 0.5% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24405 | HIGH | 8.8 | 0.5% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers... |
| CVE-2026-24404 | HIGH | 8.8 | 0.4% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v... |
| CVE-2026-24403 | HIGH | 8.8 | 0.4% | Jan 24, 2026 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v... |
| CVE-2026-24136 | HIGH | 7.5 | 0.4% | Jan 24, 2026 | Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.2... |
| CVE-2026-22995 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_wor... |
| CVE-2026-22984 | HIGH | 7.1 | 0.4% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in h... |
| CVE-2026-22980 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to ... |
| CVE-2026-24635 | HIGH | 7.5 | 0.3% | Jan 23, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-24624 | HIGH | 7.6 | 0.3% | Jan 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforu... |
| CVE-2026-24623 | HIGH | 7.1 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforu... |
| CVE-2026-24609 | HIGH | 7.5 | 0.3% | Jan 23, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-24608 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-24572 | HIGH | 8.5 | 0.3% | Jan 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel... |
| CVE-2026-24538 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-24531 | HIGH | 7.5 | 0.5% | Jan 23, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-0994 | HIGH | 7.5 | 0.7% | Jan 23, 2026 | A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recur... |
| CVE-2026-22273 | HIGH | 8.8 | 0.3% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default C... |
| CVE-2026-22271 | HIGH | 7.5 | 0.2% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi... |
| CVE-2026-0603 | HIGH | 8.3 | 0.8% | Jan 23, 2026 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerab... |
| CVE-2026-0796 | HIGH | 8.8 | 1.5% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2026-0795 | HIGH | 8.8 | 1.3% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2026-0790 | HIGH | 7.5 | 0.7% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote ... |
| CVE-2026-0789 | HIGH | 7.5 | 0.6% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Inclusion of Authentication Cookie in Response Body Information Disclosure Vulnerabili... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now