Skip to main content

Year archive

CVEs published in 2026

Archive summary

47,666 CVEs published in 2026 — 5,246 Critical, 18,960 High, 19,001 Medium, 3,879 Low, 580 Unrated.

CVE-2026-23476

Published Feb 2, 2026

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messa…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-22780

Published Feb 2, 2026

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for…

CVSS 4.4 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-22778

Published Feb 2, 2026

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an e…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
40.7
Vendor/product tagsBeta · best-effort

CVE-2026-1778

Published Feb 2, 2026

Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incor…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-1777

Published Feb 2, 2026

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A thi…

CVSS 8.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-0924

Published Feb 2, 2026

BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-70960

Published Feb 2, 2026

A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted pa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70959

Published Feb 2, 2026

A stored cross-site scripting (XSS) vulnerability in the Jobs module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payl…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70958

Published Feb 2, 2026

Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute arbitrary Javascript in the context of t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6927

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php, includes/api/ApiQueryBlocks.Php.…

CVSS 2.3 · Low

CVE-2025-6597

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.…

CVSS 0.0 · Unrated

CVE-2025-6596

Published Feb 2, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. This vulnerability is associated with pro…

CVSS 0.0 · Unrated

CVE-2025-6595

Published Feb 2, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaVie…

CVSS 0.0 · Unrated

CVE-2025-6594

Published Feb 2, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with…

CVSS 0.0 · Unrated

CVE-2025-6593

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.Php. This issue affects MediaWiki: from 1.27.0 before 1.39…

CVSS 2.1 · Low

CVE-2025-6592

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects AbuseFilter: from fe0b1cb…

CVSS 2.1 · Low

CVE-2025-6591

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php. This issue affects MediaWiki: from * b…

CVSS 0.0 · Unrated

CVE-2025-6590

Published Feb 2, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/f…

CVSS 4.6 · Medium

CVE-2025-6589

Published Feb 2, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php. This issue affects MediaWiki: >=…

CVSS 2.1 · Low

CVE-2025-69207

Published Feb 2, 2026

Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by man…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66480

Published Feb 2, 2026

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload funct…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36436

Published Feb 2, 2026

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007  is vulnerable to sto…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36253

Published Feb 2, 2026

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36238

Published Feb 2, 2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain se…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36194

Published Feb 2, 2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific…

CVSS 2.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 43,201-43,225 of 47,666 CVEsPage 1729 of 1907