Skip to main content

Year archive

CVEs published in 2026

Archive summary

50,085 CVEs published in 2026 — 5,472 Critical, 19,916 High, 19,860 Medium, 3,956 Low, 881 Unrated.

CVE-2025-15281

Published Jan 20, 2026

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_w…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-14377

Published Jan 20, 2026

A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. Thi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-14376

Published Jan 20, 2026

A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-14027

Published Jan 20, 2026

Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memor…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-11743

Published Jan 20, 2026

A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverabl…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-1183

Published Jan 20, 2026

HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user i…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-1180

Published Jan 20, 2026

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arb…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-41081

Published Jan 20, 2026

Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-41025

Published Jan 20, 2026

Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between par…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-41024

Published Jan 20, 2026

Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between par…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40679

Published Jan 20, 2026

HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to '/category_produ…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40644

Published Jan 20, 2026

Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execute JavaScript code in the victim's browser by sending them a…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-14369

Published Jan 20, 2026

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calcul…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-41084

Published Jan 20, 2026

Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed mali…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-14533

Published Jan 20, 2026

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' fun…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2025-41768

Published Jan 20, 2026

An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generatio…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-0895

Published Jan 20, 2026

The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-…

CVSS 5.2 · Medium
evidence mentions
3
Buzz score
23.9
Showing 47,676-47,700 of 50,085 CVEsPage 1908 of 2004