Skip to main content

Year archive

CVEs published in 2026

Archive summary

43,259 CVEs published in 2026 — 4,574 Critical, 17,163 High, 17,428 Medium, 3,603 Low, 491 Unrated.

CVE-2025-67835

Published Jan 14, 2026

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22211

Published Jan 14, 2026

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 n…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2025-67399

Published Jan 14, 2026

An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14242

Published Jan 14, 2026

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated a…

CVSS 6.5 · Medium

CVE-2026-22820

Published Jan 14, 2026

Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. Thi…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22240

Published Jan 14, 2026

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22239

Published Jan 14, 2026

The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22238

Published Jan 14, 2026

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending spec…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22237

Published Jan 14, 2026

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending sp…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22236

Published Jan 14, 2026

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending sp…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9142

Published Jan 14, 2026

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

CVSS 7.5 · High

CVE-2025-71144

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure context reset on disconnect() After the blamed commit below, if the MPC subflow is already in T…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-71143

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before accessing .hws Commit f316cdff8d67 ("clk: Annotate struct clk…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71142

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition A warning was triggered as follows: WARNING: kernel/cgro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-71141

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/tilcdc: Fix removal actions in case of failed probe The drm_kms_helper_poll_fini() and drm_atomic_helper_…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-71140

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Use spinlock for context list protection lock Previously a mutex was added to protec…

CVSS N/A · Unrated

CVE-2025-71139

Published Jan 14, 2026

In the Linux kernel, the following vulnerability has been resolved: kernel/kexec: fix IMA when allocation happens in CMA area *** Bug description *** When I tested kexec with t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 41,476-41,500 of 43,259 CVEsPage 1660 of 1731