2026 CVE Vulnerabilities
56,373 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21637 | HIGH | 7.5 | 1.1% | Jan 20, 2026 | A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCall... |
| CVE-2026-0726 | HIGH | 8.1 | 0.5% | Jan 20, 2026 | The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versi... |
| CVE-2026-1222 | HIGH | 8.6 | 0.6% | Jan 20, 2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privi... |
| CVE-2026-0908 | HIGH | 8.8 | 0.3% | Jan 20, 2026 | Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap co... |
| CVE-2026-0902 | HIGH | 8.8 | 0.3% | Jan 20, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out o... |
| CVE-2026-0900 | HIGH | 8.8 | 0.3% | Jan 20, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially expl... |
| CVE-2026-0899 | HIGH | 8.8 | 0.4% | Jan 20, 2026 | Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially explo... |
| CVE-2026-23949 | HIGH | 8.6 | 0.5% | Jan 20, 2026 | jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Sli... |
| CVE-2026-1203 | HIGH | 8.1 | 0.7% | Jan 20, 2026 | A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crm... |
| CVE-2026-1195 | HIGH | 7.5 | 0.2% | Jan 20, 2026 | A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of th... |
| CVE-2026-22219 | HIGH | 7.7 | 4.4% | Jan 20, 2026 | Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element upda... |
| CVE-2026-1194 | HIGH | 7.5 | 0.7% | Jan 20, 2026 | A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The... |
| CVE-2026-1193 | HIGH | 8.8 | 0.3% | Jan 19, 2026 | A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cac... |
| CVE-2026-1192 | HIGH | 7.3 | 6.1% | Jan 19, 2026 | A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unkn... |
| CVE-2026-23880 | HIGH | 7.3 | 0.2% | Jan 19, 2026 | OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Centra... |
| CVE-2026-1175 | HIGH | 7.5 | 0.4% | Jan 19, 2026 | A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql... |
| CVE-2026-23850 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted s... |
| CVE-2026-1174 | HIGH | 7.5 | 0.7% | Jan 19, 2026 | A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown function of the file /graphql... |
| CVE-2026-23845 | HIGH | 7.5 | 0.4% | Jan 19, 2026 | Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request ... |
| CVE-2026-23843 | HIGH | 7.1 | 0.2% | Jan 19, 2026 | teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients... |
| CVE-2026-23842 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 ... |
| CVE-2026-23838 | HIGH | 8.7 | 0.4% | Jan 19, 2026 | Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and pr... |
| CVE-2026-1172 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | A vulnerability has been found in birkir prime up to 0.4.0.beta.0. The affected element is an unknown function of the fi... |
| CVE-2026-1171 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | A flaw has been found in birkir prime up to 0.4.0.beta.0. Impacted is an unknown function of the file /graphql of the co... |
| CVE-2026-23836 | HIGH | 8.8 | 0.4% | Jan 19, 2026 | HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now