2026 CVE Vulnerabilities
56,866 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0500 | HIGH | 8.8 | 0.4% | Jan 13, 2026 | Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe... |
| CVE-2026-0498 | HIGH | 7.2 | 0.4% | Jan 13, 2026 | SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the fu... |
| CVE-2026-0492 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switc... |
| CVE-2026-22812 | HIGH | 8.8 | 17.0% | Jan 12, 2026 | OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv... |
| CVE-2026-22805 | HIGH | 8.6 | 0.2% | Jan 12, 2026 | Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that ... |
| CVE-2026-22801 | HIGH | 7.8 | 0.1% | Jan 12, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-22695 | HIGH | 7.1 | 0.2% | Jan 12, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-22799 | HIGH | 8.8 | 0.6% | Jan 12, 2026 | Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-a... |
| CVE-2026-22794 | HIGH | 8.8 | 0.4% | Jan 12, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin ... |
| CVE-2026-22789 | HIGH | 8.8 | 0.2% | Jan 12, 2026 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 con... |
| CVE-2026-22788 | HIGH | 8.2 | 0.5% | Jan 12, 2026 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2... |
| CVE-2026-22786 | HIGH | 7.2 | 0.9% | Jan 12, 2026 | Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulner... |
| CVE-2026-22783 | HIGH | 8.1 | 0.3% | Jan 12, 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior... |
| CVE-2026-22776 | HIGH | 7.5 | 0.4% | Jan 12, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of S... |
| CVE-2026-22771 | HIGH | 8.8 | 0.6% | Jan 12, 2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway... |
| CVE-2026-22200 | HIGH | 7.5 | 73.1% | Jan 12, 2026 | Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerabi... |
| CVE-2026-0855 | HIGH | 8.8 | 1.1% | Jan 12, 2026 | Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remot... |
| CVE-2026-0854 | HIGH | 8.8 | 1.0% | Jan 12, 2026 | Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote ... |
| CVE-2026-0850 | HIGH | 7.2 | 0.3% | Jan 11, 2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function... |
| CVE-2026-0841 | HIGH | 8.8 | 3.4% | Jan 11, 2026 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof... |
| CVE-2026-0840 | HIGH | 8.8 | 3.7% | Jan 11, 2026 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function s... |
| CVE-2026-0839 | HIGH | 8.8 | 1.0% | Jan 11, 2026 | A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecuri... |
| CVE-2026-0838 | HIGH | 8.8 | 3.4% | Jan 11, 2026 | A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/Co... |
| CVE-2026-0837 | HIGH | 8.8 | 3.4% | Jan 11, 2026 | A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFir... |
| CVE-2026-0836 | HIGH | 8.8 | 0.8% | Jan 11, 2026 | A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /gof... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now