Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,963 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,282 Medium, 3,585 Low, 482 Unrated.

CVE-2026-0696

Published Jan 16, 2026

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0695

Published Jan 16, 2026

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under spe…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-15104

Published Jan 16, 2026

Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0616

Published Jan 16, 2026

TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into the internal TheLibrarian backend system. The vendor has fix…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0615

Published Jan 16, 2026

The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running processes within TheLibrarian backend. The vendor has fixe…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0613

Published Jan 16, 2026

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0612

Published Jan 16, 2026

The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which ca…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-14894

Published Jan 16, 2026

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE thro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14510

Published Jan 16, 2026

Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, fro…

CVSS 9.2 · Critical

CVE-2025-14435

Published Jan 16, 2026

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68675

Published Jan 16, 2026

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68438

Published Jan 16, 2026

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Ren…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59870

Published Jan 16, 2026

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14844

Published Jan 16, 2026

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2026-22876

Published Jan 16, 2026

Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploited, arbitrary files on the affected p…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-20894

Published Jan 16, 2026

Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If an attacking administrator configures the affected product w…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-20759

Published Jan 16, 2026

OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user with the low("monitoring user"…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-1004

Published Jan 16, 2026

The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_p…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-0913

Published Jan 16, 2026

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcod…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-60021

Published Jan 16, 2026

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14822

Published Jan 16, 2026

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP req…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14757

Published Jan 16, 2026

The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination w…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12007

Published Jan 16, 2026

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.

CVSS 8.4 · High

CVE-2025-12006

Published Jan 16, 2026

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image.

CVSS 7.2 · High
Showing 40,876-40,900 of 42,963 CVEsPage 1636 of 1719