2026 CVE Vulnerabilities
45,829 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25896 | CRITICAL | 9.3 | 0.5% | Feb 20, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-2848 | CRITICAL | 9.8 | 0.3% | Feb 20, 2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-2333 | CRITICAL | 9.8 | 1.0% | Feb 20, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I... |
| CVE-2026-26747 | CRITICAL | 9.1 | 0.4% | Feb 20, 2026 | A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro... |
| CVE-2026-26725 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate ... |
| CVE-2026-26722 | CRITICAL | 9.4 | 0.3% | Feb 20, 2026 | An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privi... |
| CVE-2026-26093 | CRITICAL | 9.8 | 1.1% | Feb 20, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command I... |
| CVE-2026-25715 | CRITICAL | 9.8 | 0.6% | Feb 20, 2026 | The web management interface of the device allows the administrator username and password to be set to blank values. On... |
| CVE-2026-24956 | CRITICAL | 9.3 | 0.2% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download ... |
| CVE-2026-22384 | CRITICAL | 9.8 | 0.3% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injecti... |
| CVE-2026-21627 | CRITICAL | 9.5 | 0.4% | Feb 20, 2026 | The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax... |
| CVE-2026-26988 | CRITICAL | 9.1 | 7.4% | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL ... |
| CVE-2026-26974 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo... |
| CVE-2026-27002 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand... |
| CVE-2026-27476 | CRITICAL | 9.8 | 2.6% | Feb 19, 2026 | RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins... |
| CVE-2026-27475 | CRITICAL | 9.2 | 0.8% | Feb 19, 2026 | SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat... |
| CVE-2026-26057 | CRITICAL | 9.1 | 0.3% | Feb 19, 2026 | Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious ... |
| CVE-2026-2409 | CRITICAL | 9.3 | 0.2% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit... |
| CVE-2026-26339 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg... |
| CVE-2026-26338 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th... |
| CVE-2026-26030 | CRITICAL | 9.9 | 2.9% | Feb 19, 2026 | Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to ... |
| CVE-2026-23549 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2026-23542 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T... |
| CVE-2026-2731 | CRITICAL | 10 | 0.5% | Feb 19, 2026 | Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow... |
| CVE-2026-2691 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now