2026 CVE Vulnerabilities
45,497 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27847 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connec... |
| CVE-2026-27702 | CRITICAL | 9 | 0.3% | Feb 25, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un... |
| CVE-2026-3187 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f... |
| CVE-2026-27699 | CRITICAL | 9.8 | 0.5% | Feb 25, 2026 | The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2... |
| CVE-2026-2624 | CRITICAL | 9.8 | 2.2% | Feb 25, 2026 | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Gene... |
| CVE-2026-0704 | CRITICAL | 9.1 | 0.3% | Feb 25, 2026 | In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API ... |
| CVE-2026-3164 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the fil... |
| CVE-2026-3153 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-3152 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the f... |
| CVE-2026-3151 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of t... |
| CVE-2026-25785 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlie... |
| CVE-2026-3148 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown funct... |
| CVE-2026-27744 | CRITICAL | 9.8 | 0.9% | Feb 25, 2026 | The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the fo... |
| CVE-2026-27743 | CRITICAL | 9.8 | 0.6% | Feb 25, 2026 | The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the refer... |
| CVE-2026-27641 | CRITICAL | 9.8 | 1.0% | Feb 25, 2026 | Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versio... |
| CVE-2026-27637 | CRITICAL | 9.8 | 0.7% | Feb 25, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's... |
| CVE-2026-27597 | CRITICAL | 10 | 0.9% | Feb 25, 2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possibl... |
| CVE-2026-27626 | CRITICAL | 9.9 | 0.4% | Feb 25, 2026 | OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, Oliv... |
| CVE-2026-27607 | CRITICAL | 9.1 | 0.3% | Feb 25, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS d... |
| CVE-2026-27606 | CRITICAL | 9.8 | 1.4% | Feb 25, 2026 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (sp... |
| CVE-2026-3135 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of t... |
| CVE-2026-3134 | CRITICAL | 9.8 | 0.3% | Feb 25, 2026 | A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function... |
| CVE-2026-3133 | CRITICAL | 9.8 | 0.4% | Feb 25, 2026 | A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processin... |
| CVE-2026-22553 | CRITICAL | 9.8 | 1.4% | Feb 24, 2026 | All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web in... |
| CVE-2026-21410 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now