Skip to main content

Year archive

CVEs published in 2026

Archive summary

43,259 CVEs published in 2026 — 4,574 Critical, 17,163 High, 17,428 Medium, 3,603 Low, 491 Unrated.

CVE-2025-15416

Published Jan 1, 2026

A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulatio…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15415

Published Jan 1, 2026

A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. T…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15414

Published Jan 1, 2026

A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service/theme/git_fetcher.go of the component Theme Fetching API.…

CVSS 2.0 · Low

CVE-2025-15413

Published Jan 1, 2026

A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m3_exec.h. Performing a manipulation results in memory corru…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15412

Published Jan 1, 2026

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompi…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15411

Published Jan 1, 2026

A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of th…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-69203

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68620

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-68619

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages throu…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68273

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55065

Published Jan 1, 2026

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS 7.5 · High

CVE-2025-15410

Published Jan 1, 2026

A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argum…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15409

Published Jan 1, 2026

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executin…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-21437

Published Jan 1, 2026

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the ins…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-21436

Published Jan 1, 2026

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installat…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-21428

Published Jan 1, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not check for CR & LF characters in…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-68272

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66398

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath…

CVSS 9.6 · Critical
Buzz score
5.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15408

Published Jan 1, 2026

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argumen…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15407

Published Jan 1, 2026

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48769

Published Jan 1, 2026

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer var…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48768

Published Jan 1, 2026

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47411

Published Jan 1, 2026

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14627

Published Jan 1, 2026

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due t…

CVSS 6.4 · Medium
Showing 43,226-43,250 of 43,259 CVEsPage 1730 of 1731