Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,966 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,284 Medium, 3,586 Low, 482 Unrated.

CVE-2026-1109

Published Jan 18, 2026

A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is the function rtsp_parse_request. The manipulation results in…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1108

Published Jan 18, 2026

A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affected element is the function rtsp_rely_dumps. The manipulation…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1107

Published Jan 18, 2026

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a mani…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1106

Published Jan 18, 2026

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of th…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1105

Published Jan 18, 2026

A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to s…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1066

Published Jan 17, 2026

A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. T…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1064

Published Jan 17, 2026

A vulnerability was found in bastillion-io Bastillion up to 4.0.1. This issue affects some unknown processing of the file src/main/java/io/bastillion/manage/control/SystemKtrl.jav…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-1063

Published Jan 17, 2026

A vulnerability has been found in bastillion-io Bastillion up to 4.0.1. This vulnerability affects unknown code of the file src/main/java/io/bastillion/manage/control/AuthKeysKtrl…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-1062

Published Jan 17, 2026

A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argu…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-1061

Published Jan 17, 2026

A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1059

Published Jan 17, 2026

A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /s…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1050

Published Jan 17, 2026

A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.ja…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-1049

Published Jan 17, 2026

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument T…

CVSS 2.0 · Low
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1048

Published Jan 17, 2026

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument Ti…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-15532

Published Jan 17, 2026

A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consump…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15531

Published Jan 17, 2026

A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15530

Published Jan 17, 2026

A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0725

Published Jan 17, 2026

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2025-8615

Published Jan 17, 2026

The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due…

CVSS 6.4 · Medium

CVE-2025-14078

Published Jan 17, 2026

The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on…

CVSS 5.3 · Medium

CVE-2025-10484

Published Jan 17, 2026

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-14478

Published Jan 17, 2026

The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality.…

CVSS 7.5 · High

CVE-2025-12129

Published Jan 17, 2026

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/…

CVSS 5.3 · Medium

CVE-2026-0833

Published Jan 17, 2026

The Team Section Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block in all versions up to, and including, 2.0.0 due to insufficient inp…

CVSS 6.4 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-0808

Published Jan 17, 2026

The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
26.1
Showing 40,751-40,775 of 42,966 CVEsPage 1631 of 1719