2026 CVE Vulnerabilities
45,460 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27494 | CRITICAL | 9.9 | 0.4% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user... |
| CVE-2026-27493 | CRITICAL | 9 | 1.1% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres... |
| CVE-2026-27575 | CRITICAL | 9.1 | 0.4% | Feb 25, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to ... |
| CVE-2026-27148 | CRITICAL | 9.6 | 0.5% | Feb 25, 2026 | Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23... |
| CVE-2026-25997 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` re... |
| CVE-2026-25959 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` pas... |
| CVE-2026-25955 | CRITICAL | 9.8 | 0.5% | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface... |
| CVE-2026-25953 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface... |
| CVE-2026-25952 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` deref... |
| CVE-2026-0542 | CRITICAL | 9.2 | 0.6% | Feb 25, 2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This ... |
| CVE-2026-22720 | CRITICAL | 9 | 0.4% | Feb 25, 2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create... |
| CVE-2026-27739 | CRITICAL | 9.2 | 0.5% | Feb 25, 2026 | The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17... |
| CVE-2026-21902 | CRITICAL | 9.8 | 17.7% | Feb 25, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juni... |
| CVE-2026-27849 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP... |
| CVE-2026-27727 | CRITICAL | 9.8 | 0.8% | Feb 25, 2026 | mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI f... |
| CVE-2026-20129 | CRITICAL | 9.8 | 0.7% | Feb 25, 2026 | A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote a... |
| CVE-2026-20127 | CRITICAL | 10 | 57.8% | Feb 25, 2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalys... |
| CVE-2026-27848 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection... |
| CVE-2026-27847 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connec... |
| CVE-2026-27702 | CRITICAL | 9 | 0.3% | Feb 25, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un... |
| CVE-2026-3187 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f... |
| CVE-2026-27699 | CRITICAL | 9.8 | 0.5% | Feb 25, 2026 | The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2... |
| CVE-2026-2624 | CRITICAL | 9.8 | 2.2% | Feb 25, 2026 | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Gene... |
| CVE-2026-0704 | CRITICAL | 9.1 | 0.3% | Feb 25, 2026 | In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API ... |
| CVE-2026-3164 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now