Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,963 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,282 Medium, 3,585 Low, 482 Unrated.

CVE-2026-0383

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24935

Published Feb 3, 2026

A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional a…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24934

Published Feb 3, 2026

The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticate…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24933

Published Feb 3, 2026

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an un…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24932

Published Feb 3, 2026

The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67484

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affects MediaWiki: from * before 1.…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67483

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67482

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation Scribunto, Wikimedia Foundation luasandbox. This vulnerability is associated with program files includes/Engines/LuaCommon/lualib/mwInit.Lua,…

CVSS 1.7 · Low

CVE-2025-67481

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67480

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php. This issue affects MediaWiki: from *…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67479

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Cite. This vulnerability is associated with program files includes/Parser/CoreParserFunctions.Php, includes/P…

CVSS 0.0 · Unrated

CVE-2025-67478

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.3…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67477

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-67476

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWi…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-67475

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-61658

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/GlobalContributions/GlobalContributionsPager.Php. This issue affects Chec…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-61657

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. This vulnerability is associated with pro…

CVSS 0.0 · Unrated

CVE-2025-61656

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated wi…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-61655

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated wi…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-61654

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation Thanks. This vulnerability is associated with program files includes/ThanksQueryHelper.Php. This issue affects Thanks: from * before 1.43.4,…

CVSS 0.0 · Unrated

CVE-2025-61653

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php. This issue affects TextExtracts: from * bef…

CVSS 2.7 · Low

CVE-2025-61652

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation DiscussionTools.This issue affects DiscussionTools: from * before 1.43.4, 1.44.1.

CVSS 2.7 · Low

CVE-2025-61651

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-58383

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security contro…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58382

Published Feb 3, 2026

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 38,426-38,450 of 42,963 CVEsPage 1538 of 1719