2026 CVE Vulnerabilities
45,453 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2584 | CRITICAL | 9.3 | 0.4% | Mar 2, 2026 | A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe... |
| CVE-2026-3422 | CRITICAL | 9.8 | 0.8% | Mar 2, 2026 | U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote a... |
| CVE-2026-3413 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the f... |
| CVE-2026-3000 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r... |
| CVE-2026-2999 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r... |
| CVE-2026-3411 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is s... |
| CVE-2026-3410 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-3406 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of t... |
| CVE-2026-3400 | CRITICAL | 9.8 | 0.9% | Mar 2, 2026 | A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionalit... |
| CVE-2026-3395 | CRITICAL | 9.8 | 0.5% | Mar 1, 2026 | A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/p... |
| CVE-2026-28562 | CRITICAL | 9.8 | 0.4% | Feb 28, 2026 | wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause ... |
| CVE-2026-28517 | CRITICAL | 9.8 | 5.6% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.ph... |
| CVE-2026-28411 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on... |
| CVE-2026-28408 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.p... |
| CVE-2026-28268 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil... |
| CVE-2026-28231 | CRITICAL | 9.1 | 0.6% | Feb 27, 2026 | pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer o... |
| CVE-2026-27707 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and ... |
| CVE-2026-2880 | CRITICAL | 9.1 | 0.4% | Feb 27, 2026 | A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-sc... |
| CVE-2026-27755 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th... |
| CVE-2026-27751 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot... |
| CVE-2026-2293 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fas... |
| CVE-2026-2750 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tick... |
| CVE-2026-2751 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web ... |
| CVE-2026-24352 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa... |
| CVE-2026-21660 | CRITICAL | 9.8 | 0.2% | Feb 27, 2026 | Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in F... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now