2026 CVE Vulnerabilities
56,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21906 | HIGH | 8.7 | 0.5% | Jan 15, 2026 | An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks J... |
| CVE-2026-21905 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Jun... |
| CVE-2026-21903 | HIGH | 7.1 | 0.4% | Jan 15, 2026 | A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a ... |
| CVE-2026-0203 | HIGH | 7.1 | 0.2% | Jan 15, 2026 | An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an... |
| CVE-2026-23622 | HIGH | 8.8 | 0.2% | Jan 15, 2026 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_v... |
| CVE-2026-23520 | HIGH | 8 | 1.6% | Jan 15, 2026 | Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane... |
| CVE-2026-22803 | HIGH | 7.5 | 0.5% | Jan 15, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,... |
| CVE-2026-22775 | HIGH | 7.5 | 0.6% | Jan 15, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-22774 | HIGH | 7.5 | 0.6% | Jan 15, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-0227 | HIGH | 7.5 | 0.7% | Jan 15, 2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (... |
| CVE-2026-22265 | HIGH | 7.5 | 2.1% | Jan 15, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injecti... |
| CVE-2026-22646 | HIGH | 7.5 | 0.4% | Jan 15, 2026 | Certain error messages returned by the application expose internal system details that should not be visible to end user... |
| CVE-2026-22644 | HIGH | 7.5 | 0.5% | Jan 15, 2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu... |
| CVE-2026-0897 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through ... |
| CVE-2026-22918 | HIGH | 8.2 | 0.3% | Jan 15, 2026 | An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions thr... |
| CVE-2026-22917 | HIGH | 7.5 | 0.5% | Jan 15, 2026 | Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service. |
| CVE-2026-22911 | HIGH | 7.5 | 0.5% | Jan 15, 2026 | Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre... |
| CVE-2026-0421 | HIGH | 7 | 0.1% | Jan 14, 2026 | A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh... |
| CVE-2026-23512 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability wh... |
| CVE-2026-0861 | HIGH | 8.4 | 0.4% | Jan 14, 2026 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C... |
| CVE-2026-23498 | HIGH | 7.2 | 0.4% | Jan 14, 2026 | Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array a... |
| CVE-2026-22036 | HIGH | 7.5 | 0.4% | Jan 14, 2026 | Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is ... |
| CVE-2026-22856 | HIGH | 8.1 | 0.3% | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP threa... |
| CVE-2026-21889 | HIGH | 7.5 | 0.3% | Jan 14, 2026 | Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server... |
| CVE-2026-22240 | HIGH | 7.5 | 3.0% | Jan 14, 2026 | The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now