Skip to main content

Year archive

CVEs published in 2026

Archive summary

42,966 CVEs published in 2026 — 4,543 Critical, 17,071 High, 17,284 Medium, 3,586 Low, 482 Unrated.

CVE-2025-15408

Published Jan 1, 2026

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argumen…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15407

Published Jan 1, 2026

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48769

Published Jan 1, 2026

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer var…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48768

Published Jan 1, 2026

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47411

Published Jan 1, 2026

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14627

Published Jan 1, 2026

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due t…

CVSS 6.4 · Medium

CVE-2025-14428

Published Jan 1, 2026

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to…

CVSS 4.3 · Medium

CVE-2025-66023

Published Jan 1, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client compone…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15405

Published Jan 1, 2026

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0544

Published Jan 1, 2026

A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-11157

Published Jan 1, 2026

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/in…

CVSS 7.8 · High
evidence mentions
6
Buzz score
34.0

CVE-2025-13820

Published Jan 1, 2026

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowin…

CVSS 5.3 · Medium

CVE-2025-69413

Published Jan 1, 2026

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69412

Published Jan 1, 2026

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE…

CVSS 3.4 · Low
Showing 42,951-42,966 of 42,966 CVEsPage 1719 of 1719