2026 CVE Vulnerabilities
45,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2952 | CRITICAL | 9.8 | 4.5% | Feb 22, 2026 | A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the... |
| CVE-2026-2944 | CRITICAL | 9.8 | 3.7% | Feb 22, 2026 | A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function s... |
| CVE-2026-2912 | CRITICAL | 9.8 | 0.3% | Feb 22, 2026 | A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /syst... |
| CVE-2026-2894 | CRITICAL | 9.1 | 0.4% | Feb 21, 2026 | A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of ... |
| CVE-2026-2867 | CRITICAL | 9.8 | 0.3% | Feb 21, 2026 | A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2026-27574 | CRITICAL | 9.9 | 0.5% | Feb 21, 2026 | OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript mon... |
| CVE-2026-2865 | CRITICAL | 9.8 | 0.3% | Feb 21, 2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of t... |
| CVE-2026-27471 | CRITICAL | 9.1 | 0.3% | Feb 21, 2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 1... |
| CVE-2026-27211 | CRITICAL | 10 | 0.5% | Feb 21, 2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary... |
| CVE-2026-27197 | CRITICAL | 9.1 | 0.4% | Feb 21, 2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a criti... |
| CVE-2026-27194 | CRITICAL | 9.8 | 0.7% | Feb 21, 2026 | D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution thro... |
| CVE-2026-27168 | CRITICAL | 9.8 | 0.4% | Feb 21, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. A... |
| CVE-2026-2635 | CRITICAL | 9.8 | 1.0% | Feb 20, 2026 | MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass... |
| CVE-2026-2039 | CRITICAL | 9.8 | 0.7% | Feb 20, 2026 | GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote atta... |
| CVE-2026-2038 | CRITICAL | 9.8 | 0.7% | Feb 20, 2026 | GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attac... |
| CVE-2026-27112 | CRITICAL | 9.9 | 0.4% | Feb 20, 2026 | Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the b... |
| CVE-2026-27190 | CRITICAL | 9.8 | 2.2% | Feb 20, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in D... |
| CVE-2026-25896 | CRITICAL | 9.3 | 0.5% | Feb 20, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-2848 | CRITICAL | 9.8 | 0.3% | Feb 20, 2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-2333 | CRITICAL | 9.8 | 1.0% | Feb 20, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I... |
| CVE-2026-26747 | CRITICAL | 9.1 | 0.4% | Feb 20, 2026 | A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro... |
| CVE-2026-26725 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate ... |
| CVE-2026-26722 | CRITICAL | 9.4 | 0.3% | Feb 20, 2026 | An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privi... |
| CVE-2026-26093 | CRITICAL | 9.8 | 1.1% | Feb 20, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I... |
| CVE-2026-25715 | CRITICAL | 9.8 | 0.6% | Feb 20, 2026 | The web management interface of the device allows the administrator username and password to be set to blank values. On... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now