2026 CVE Vulnerabilities
56,373 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1111 | HIGH | 7.2 | 0.6% | Jan 18, 2026 | A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/pub... |
| CVE-2026-1110 | HIGH | 7.8 | 0.3% | Jan 18, 2026 | A flaw has been found in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. This affects the function rtsp_p... |
| CVE-2026-1109 | HIGH | 7.8 | 0.2% | Jan 18, 2026 | A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is t... |
| CVE-2026-1108 | HIGH | 7.8 | 0.2% | Jan 18, 2026 | A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affecte... |
| CVE-2026-1066 | HIGH | 8.8 | 5.0% | Jan 17, 2026 | A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /... |
| CVE-2026-1050 | HIGH | 7.3 | 0.4% | Jan 17, 2026 | A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file so... |
| CVE-2026-0517 | HIGH | 7.5 | 0.3% | Jan 17, 2026 | CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can ... |
| CVE-2026-22865 | HIGH | 7.4 | 0.1% | Jan 16, 2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d... |
| CVE-2026-22816 | HIGH | 7.4 | 0.1% | Jan 16, 2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d... |
| CVE-2026-21223 | HIGH | 7.1 | 0.3% | Jan 16, 2026 | Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feat... |
| CVE-2026-20960 | HIGH | 8 | 0.5% | Jan 16, 2026 | Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. |
| CVE-2026-23742 | HIGH | 8.8 | 0.5% | Jan 16, 2026 | Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was... |
| CVE-2026-23735 | HIGH | 8.7 | 0.5% | Jan 16, 2026 | GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extend... |
| CVE-2026-23723 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide... |
| CVE-2026-23535 | HIGH | 8 | 0.3% | Jan 16, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could wri... |
| CVE-2026-23490 | HIGH | 7.5 | 0.7% | Jan 16, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to mem... |
| CVE-2026-0629 | HIGH | 8.7 | 0.4% | Jan 16, 2026 | Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models all... |
| CVE-2026-23529 | HIGH | 7.7 | 0.4% | Jan 16, 2026 | Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to... |
| CVE-2026-23523 | HIGH | 8.8 | 6.3% | Jan 16, 2026 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0... |
| CVE-2026-22782 | HIGH | 7.5 | 0.5% | Jan 16, 2026 | RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signat... |
| CVE-2026-21625 | HIGH | 8.8 | 0.3% | Jan 16, 2026 | User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by ... |
| CVE-2026-0616 | HIGH | 7.5 | 0.3% | Jan 16, 2026 | TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into t... |
| CVE-2026-0615 | HIGH | 7.3 | 0.2% | Jan 16, 2026 | The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running ... |
| CVE-2026-0613 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used w... |
| CVE-2026-0612 | HIGH | 7.5 | 0.3% | Jan 16, 2026 | The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now