2026 CVE Vulnerabilities
45,455 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25945 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-25851 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-25114 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-25113 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-24731 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-20792 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen... |
| CVE-2026-20781 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona... |
| CVE-2026-28215 | CRITICAL | 9.1 | 0.5% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw... |
| CVE-2026-28213 | CRITICAL | 9.8 | 0.4% | Feb 26, 2026 | EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password"... |
| CVE-2026-3261 | CRITICAL | 9.8 | 0.3% | Feb 26, 2026 | A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin... |
| CVE-2026-22207 | CRITICAL | 9.8 | 0.4% | Feb 26, 2026 | OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u... |
| CVE-2026-27975 | CRITICAL | 9.8 | 0.5% | Feb 26, 2026 | Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access... |
| CVE-2026-27966 | CRITICAL | 9.8 | 33.7% | Feb 26, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent nod... |
| CVE-2026-27965 | CRITICAL | 9.9 | 0.4% | Feb 26, 2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with... |
| CVE-2026-27952 | CRITICAL | 9.9 | 0.5% | Feb 26, 2026 | Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability e... |
| CVE-2026-27941 | CRITICAL | 9.9 | 0.4% | Feb 26, 2026 | OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open... |
| CVE-2026-27837 | CRITICAL | 9.8 | 0.3% | Feb 26, 2026 | Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete ... |
| CVE-2026-27812 | CRITICAL | 9.1 | 0.2% | Feb 26, 2026 | Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vuln... |
| CVE-2026-27809 | CRITICAL | 9.1 | 0.4% | Feb 26, 2026 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta... |
| CVE-2026-27804 | CRITICAL | 9.1 | 0.2% | Feb 26, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-27613 | CRITICAL | 9.8 | 0.7% | Feb 25, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unau... |
| CVE-2026-27577 | CRITICAL | 9.9 | 8.6% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits i... |
| CVE-2026-27495 | CRITICAL | 9.9 | 0.6% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user... |
| CVE-2026-27494 | CRITICAL | 9.9 | 0.4% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user... |
| CVE-2026-27493 | CRITICAL | 9 | 1.1% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now