2026 CVE Vulnerabilities
56,866 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0822 | HIGH | 8.8 | 0.4% | Jan 10, 2026 | A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort o... |
| CVE-2026-22777 | HIGH | 7.5 | 0.3% | Jan 10, 2026 | ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an att... |
| CVE-2026-22773 | HIGH | 7.5 | 0.4% | Jan 10, 2026 | vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users... |
| CVE-2026-22700 | HIGH | 7.5 | 0.3% | Jan 10, 2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for... |
| CVE-2026-22699 | HIGH | 7.5 | 0.4% | Jan 10, 2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for... |
| CVE-2026-22698 | HIGH | 7.5 | 0.2% | Jan 10, 2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for... |
| CVE-2026-22688 | HIGH | 8.8 | 1.7% | Jan 10, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-22589 | HIGH | 7.5 | 0.4% | Jan 10, 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5,... |
| CVE-2026-22596 | HIGH | 7.2 | 0.4% | Jan 10, 2026 | Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili... |
| CVE-2026-22595 | HIGH | 8.1 | 0.5% | Jan 10, 2026 | Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabil... |
| CVE-2026-22594 | HIGH | 8.1 | 0.4% | Jan 10, 2026 | Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabil... |
| CVE-2026-21884 | HIGH | 8.2 | 0.5% | Jan 10, 2026 | React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, ... |
| CVE-2026-22612 | HIGH | 7.8 | 0.3% | Jan 10, 2026 | Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detectio... |
| CVE-2026-22609 | HIGH | 7.8 | 0.6% | Jan 10, 2026 | Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fic... |
| CVE-2026-22608 | HIGH | 7.8 | 0.3% | Jan 10, 2026 | Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren... |
| CVE-2026-22607 | HIGH | 7.8 | 0.4% | Jan 10, 2026 | Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P... |
| CVE-2026-22606 | HIGH | 7.8 | 0.4% | Jan 10, 2026 | Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P... |
| CVE-2026-22601 | HIGH | 7.2 | 0.3% | Jan 10, 2026 | OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a regist... |
| CVE-2026-22697 | HIGH | 7.5 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22026 | HIGH | 7.5 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-22023 | HIGH | 7.5 | 0.5% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21898 | HIGH | 8.2 | 0.4% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-21897 | HIGH | 7.3 | 0.3% | Jan 10, 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2026-0830 | HIGH | 8.4 | 1.3% | Jan 9, 2026 | Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge... |
| CVE-2026-22197 | HIGH | 8.1 | 0.3% | Jan 9, 2026 | GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multipl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now