2026 CVE Vulnerabilities
45,845 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27179 | CRITICAL | 9.8 | 0.5% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. Th... |
| CVE-2026-27175 | CRITICAL | 9.8 | 6.9% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param... |
| CVE-2026-27174 | CRITICAL | 9.8 | 7.0% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console fea... |
| CVE-2026-0573 | CRITICAL | 9 | 0.6% | Feb 18, 2026 | An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects t... |
| CVE-2026-2329 | CRITICAL | 9.8 | 40.0% | Feb 18, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A ... |
| CVE-2026-2654 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of ... |
| CVE-2026-1435 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of s... |
| CVE-2026-1670 | CRITICAL | 9.8 | 0.8% | Feb 17, 2026 | The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotel... |
| CVE-2026-22769 | CRITICAL | 10 | 13.1% | Feb 17, 2026 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. Thi... |
| CVE-2026-23647 | CRITICAL | 9.8 | 0.6% | Feb 17, 2026 | Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that... |
| CVE-2026-2616 | CRITICAL | 9.8 | 1.3% | Feb 17, 2026 | A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the compo... |
| CVE-2026-22208 | CRITICAL | 9.6 | 0.9% | Feb 17, 2026 | OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil... |
| CVE-2026-26220 | CRITICAL | 9.3 | 0.7% | Feb 17, 2026 | LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) d... |
| CVE-2026-2439 | CRITICAL | 9.8 | 0.4% | Feb 16, 2026 | Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id fun... |
| CVE-2026-2564 | CRITICAL | 9.2 | 0.5% | Feb 16, 2026 | A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an u... |
| CVE-2026-2577 | CRITICAL | 10 | 0.6% | Feb 16, 2026 | The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by ... |
| CVE-2026-2550 | CRITICAL | 9.8 | 0.6% | Feb 16, 2026 | A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file ... |
| CVE-2026-2532 | CRITICAL | 9.8 | 0.2% | Feb 16, 2026 | A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the fil... |
| CVE-2026-2529 | CRITICAL | 9.8 | 6.0% | Feb 16, 2026 | A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteM... |
| CVE-2026-2528 | CRITICAL | 9.8 | 5.8% | Feb 16, 2026 | A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Dele... |
| CVE-2026-2527 | CRITICAL | 9.8 | 6.0% | Feb 16, 2026 | A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bi... |
| CVE-2026-2522 | CRITICAL | 9.8 | 0.5% | Feb 16, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/... |
| CVE-2026-2521 | CRITICAL | 9.8 | 0.7% | Feb 15, 2026 | A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re... |
| CVE-2026-26369 | CRITICAL | 9.8 | 0.6% | Feb 15, 2026 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization c... |
| CVE-2026-26366 | CRITICAL | 9.8 | 0.7% | Feb 15, 2026 | eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now