Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,963 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,282 Medium, 3,585 Low, 482 Unrated.

CVE-2026-1813

Published Feb 4, 2026

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the comp…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1633

Published Feb 4, 2026

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critica…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-24514

Published Feb 3, 2026

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the va…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-24513

Published Feb 3, 2026

A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfigura…

CVSS 3.1 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-24512

Published Feb 3, 2026

A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code ex…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-1812

Published Feb 3, 2026

A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.jav…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1755

Published Feb 3, 2026

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and including, 0.…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-1632

Published Feb 3, 2026

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify con…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-1580

Published Feb 3, 2026

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can le…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-36094

Published Feb 3, 2026

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36033

Published Feb 3, 2026

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Manage…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-37087

Published Feb 3, 2026

Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts by manipulating the oldP…

CVSS 5.1 · Medium

CVE-2020-37084

Published Feb 3, 2026

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2026-25510

Published Feb 3, 2026

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authent…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25509

Published Feb 3, 2026

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authen…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25224

Published Feb 3, 2026

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a rem…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-25223

Published Feb 3, 2026

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas sp…

CVSS 7.5 · High
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2026-25155

Published Feb 3, 2026

Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25151

Published Feb 3, 2026

Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be a…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25150

Published Feb 3, 2026

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city mi…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25149

Published Feb 3, 2026

Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attac…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25148

Published Feb 3, 2026

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1811

Published Feb 3, 2026

A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1341

Published Feb 3, 2026

Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Showing 38,126-38,150 of 42,963 CVEsPage 1526 of 1719