2026 CVE Vulnerabilities
56,373 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22876 | HIGH | 7.1 | 0.5% | Jan 16, 2026 | Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vu... |
| CVE-2026-20759 | HIGH | 8.8 | 1.5% | Jan 16, 2026 | OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, whic... |
| CVE-2026-1023 | HIGH | 8.7 | 0.5% | Jan 16, 2026 | Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remot... |
| CVE-2026-1022 | HIGH | 8.7 | 0.6% | Jan 16, 2026 | Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote ... |
| CVE-2026-22863 | HIGH | 7.5 | 0.2% | Jan 15, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulner... |
| CVE-2026-22045 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Tr... |
| CVE-2026-0915 | HIGH | 7.5 | 0.6% | Jan 15, 2026 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for netw... |
| CVE-2026-21921 | HIGH | 7.1 | 0.3% | Jan 15, 2026 | A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows... |
| CVE-2026-21920 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthent... |
| CVE-2026-21918 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allo... |
| CVE-2026-21917 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks J... |
| CVE-2026-21914 | HIGH | 8.7 | 0.3% | Jan 15, 2026 | An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated... |
| CVE-2026-21913 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS ... |
| CVE-2026-21911 | HIGH | 7.1 | 0.2% | Jan 15, 2026 | An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS E... |
| CVE-2026-21910 | HIGH | 7.1 | 0.2% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N... |
| CVE-2026-21909 | HIGH | 7.1 | 0.2% | Jan 15, 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks... |
| CVE-2026-21908 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS ... |
| CVE-2026-21907 | HIGH | 8.2 | 0.2% | Jan 15, 2026 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space a... |
| CVE-2026-21906 | HIGH | 8.7 | 0.5% | Jan 15, 2026 | An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks J... |
| CVE-2026-21905 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Jun... |
| CVE-2026-21903 | HIGH | 7.1 | 0.4% | Jan 15, 2026 | A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a ... |
| CVE-2026-0203 | HIGH | 7.1 | 0.2% | Jan 15, 2026 | An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an... |
| CVE-2026-23622 | HIGH | 8.8 | 0.2% | Jan 15, 2026 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_v... |
| CVE-2026-23520 | HIGH | 8 | 1.6% | Jan 15, 2026 | Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane... |
| CVE-2026-22803 | HIGH | 7.5 | 0.5% | Jan 15, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now