2026 CVE Vulnerabilities
56,359 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21524 | HIGH | 7.4 | 0.5% | Jan 22, 2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to dis... |
| CVE-2026-21521 | HIGH | 7.4 | 0.5% | Jan 22, 2026 | Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose inf... |
| CVE-2026-21520 | HIGH | 7.5 | 1.4% | Jan 22, 2026 | Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s... |
| CVE-2026-23988 | HIGH | 7 | 0.2% | Jan 22, 2026 | Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condit... |
| CVE-2026-23954 | HIGH | 8.7 | 0.7% | Jan 22, 2026 | Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to laun... |
| CVE-2026-23953 | HIGH | 8.7 | 0.5% | Jan 22, 2026 | Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch... |
| CVE-2026-20736 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachmen... |
| CVE-2026-22279 | HIGH | 7.5 | 0.2% | Jan 22, 2026 | Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attac... |
| CVE-2026-24390 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-24367 | HIGH | 8.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2026-23978 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-23975 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-23763 | HIGH | 8.5 | 0.2% | Jan 22, 2026 | VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local p... |
| CVE-2026-22470 | HIGH | 7.6 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins ... |
| CVE-2026-22464 | HIGH | 7.5 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22402 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22401 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22355 | HIGH | 7.1 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.Th... |
| CVE-2026-1260 | HIGH | 7.8 | 0.2% | Jan 22, 2026 | Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created... |
| CVE-2026-0535 | HIGH | 8.1 | 0.6% | Jan 22, 2026 | A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cros... |
| CVE-2026-0534 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site ... |
| CVE-2026-0533 | HIGH | 8.1 | 0.6% | Jan 22, 2026 | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by... |
| CVE-2026-1329 | HIGH | 8.8 | 1.1% | Jan 22, 2026 | A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /g... |
| CVE-2026-1328 | HIGH | 8.8 | 0.8% | Jan 22, 2026 | A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the fil... |
| CVE-2026-1327 | HIGH | 8.8 | 2.6% | Jan 22, 2026 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function se... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now