2026 CVE Vulnerabilities
45,845 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26974 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo... |
| CVE-2026-27002 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand... |
| CVE-2026-27476 | CRITICAL | 9.8 | 2.6% | Feb 19, 2026 | RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins... |
| CVE-2026-27475 | CRITICAL | 9.2 | 0.8% | Feb 19, 2026 | SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat... |
| CVE-2026-26057 | CRITICAL | 9.1 | 0.3% | Feb 19, 2026 | Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious ... |
| CVE-2026-2409 | CRITICAL | 9.3 | 0.2% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suit... |
| CVE-2026-26339 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg... |
| CVE-2026-26338 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th... |
| CVE-2026-26030 | CRITICAL | 9.9 | 2.9% | Feb 19, 2026 | Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to ... |
| CVE-2026-23549 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2026-23542 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T... |
| CVE-2026-2731 | CRITICAL | 10 | 0.5% | Feb 19, 2026 | Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allow... |
| CVE-2026-2691 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct... |
| CVE-2026-2690 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown function... |
| CVE-2026-2689 | CRITICAL | 9.8 | 0.6% | Feb 19, 2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /a... |
| CVE-2026-25242 | CRITICAL | 9.8 | 0.6% | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints b... |
| CVE-2026-1994 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2026-1405 | CRITICAL | 9.8 | 3.2% | Feb 19, 2026 | The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2026-0926 | CRITICAL | 9.8 | 9.4% | Feb 19, 2026 | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.... |
| CVE-2026-2686 | CRITICAL | 9.8 | 2.3% | Feb 19, 2026 | A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file... |
| CVE-2026-2684 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted ele... |
| CVE-2026-24126 | CRITICAL | 9.1 | 0.4% | Feb 19, 2026 | Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input ... |
| CVE-2026-2682 | CRITICAL | 9.8 | 0.3% | Feb 18, 2026 | A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an u... |
| CVE-2026-25548 | CRITICAL | 9.1 | 0.8% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Co... |
| CVE-2026-27180 | CRITICAL | 9.8 | 1.1% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now