Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,985 CVEs published in 2026 — 4,543 Critical, 17,077 High, 17,292 Medium, 3,586 Low, 487 Unrated.

CVE-2025-15444

Published Jan 6, 2026

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-21439

Published Jan 6, 2026

badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control cha…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-0607

Published Jan 6, 2026

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argum…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-69230

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-69229

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usa…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69228

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memo…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69227

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed,…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69225

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-0606

Published Jan 5, 2026

A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulati…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-69226

Published Jan 5, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69224

Published Jan 5, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the p…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0625

Published Jan 5, 2026

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker t…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
36.0

CVE-2025-69223

Published Jan 5, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server.…

CVSS 7.5 · High
evidence mentions
26
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-68953

Published Jan 5, 2026

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68456

Published Jan 5, 2026

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68455

Published Jan 5, 2026

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Executi…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68454

Published Jan 5, 2026

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Executi…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68437

Published Jan 5, 2026

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68436

Published Jan 5, 2026

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potenti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68428

Published Jan 5, 2026

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusi…

CVSS 9.2 · Critical
evidence mentions
11
Buzz score
44.4
Vendor/product tagsBeta · best-effort

CVE-2025-67732

Published Jan 5, 2026

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reu…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66648

Published Jan 5, 2026

vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65110

Published Jan 5, 2026

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61916

Published Jan 5, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primar…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2026-0621

Published Jan 5, 2026

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RF…

CVSS 8.7 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 42,676-42,700 of 42,985 CVEsPage 1708 of 1720