2026 CVE Vulnerabilities
56,373 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23833 | HIGH | 7.5 | 0.3% | Jan 19, 2026 | ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2... |
| CVE-2026-23732 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbDa... |
| CVE-2026-1169 | HIGH | 8.8 | 0.2% | Jan 19, 2026 | A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. ... |
| CVE-2026-22850 | HIGH | 8.3 | 0.4% | Jan 19, 2026 | Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL... |
| CVE-2026-22037 | HIGH | 8.4 | 0.3% | Jan 19, 2026 | The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr... |
| CVE-2026-22031 | HIGH | 8.8 | 0.5% | Jan 19, 2026 | @fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @f... |
| CVE-2026-1158 | HIGH | 8.8 | 0.6% | Jan 19, 2026 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function set... |
| CVE-2026-1007 | HIGH | 7.6 | 0.2% | Jan 19, 2026 | Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny... |
| CVE-2026-1157 | HIGH | 8.8 | 0.9% | Jan 19, 2026 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the ... |
| CVE-2026-1156 | HIGH | 8.8 | 0.6% | Jan 19, 2026 | A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBa... |
| CVE-2026-1155 | HIGH | 8.8 | 0.8% | Jan 19, 2026 | A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiF... |
| CVE-2026-1150 | HIGH | 8.8 | 2.4% | Jan 19, 2026 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg o... |
| CVE-2026-1149 | HIGH | 8.8 | 2.7% | Jan 19, 2026 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg ... |
| CVE-2026-1145 | HIGH | 8.8 | 0.3% | Jan 19, 2026 | A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_... |
| CVE-2026-1144 | HIGH | 8.8 | 0.3% | Jan 19, 2026 | A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c o... |
| CVE-2026-1143 | HIGH | 8.8 | 0.7% | Jan 19, 2026 | A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg o... |
| CVE-2026-1141 | HIGH | 8.8 | 0.3% | Jan 19, 2026 | A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /a... |
| CVE-2026-1140 | HIGH | 8.8 | 0.7% | Jan 19, 2026 | A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/Config... |
| CVE-2026-1139 | HIGH | 8.8 | 0.9% | Jan 19, 2026 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /... |
| CVE-2026-1138 | HIGH | 8.8 | 0.9% | Jan 19, 2026 | A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. ... |
| CVE-2026-1137 | HIGH | 8.8 | 0.8% | Jan 19, 2026 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof... |
| CVE-2026-0943 | HIGH | 7.5 | 0.4% | Jan 19, 2026 | HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability... |
| CVE-2026-23644 | HIGH | 7.5 | 0.5% | Jan 18, 2026 | esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925... |
| CVE-2026-23525 | HIGH | 8.4 | 0.3% | Jan 18, 2026 | 1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulne... |
| CVE-2026-1112 | HIGH | 8.1 | 0.4% | Jan 18, 2026 | A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now