2026 CVE Vulnerabilities
46,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25881 | CRITICAL | 10 | 0.6% | Feb 9, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to m... |
| CVE-2026-25875 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorizatio... |
| CVE-2026-25814 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query ... |
| CVE-2026-25811 | CRITICAL | 9.1 | 0.3% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derive... |
| CVE-2026-25876 | CRITICAL | 9.1 | 0.2% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes... |
| CVE-2026-25810 | CRITICAL | 9.1 | 0.2% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes... |
| CVE-2026-25809 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation en... |
| CVE-2026-25057 | CRITICAL | 9.1 | 0.5% | Feb 9, 2026 | MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able ... |
| CVE-2026-24679 | CRITICAL | 9.1 | 0.5% | Feb 9, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied... |
| CVE-2026-24677 | CRITICAL | 9.1 | 0.5% | Feb 9, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts serv... |
| CVE-2026-25848 | CRITICAL | 9.8 | 0.4% | Feb 9, 2026 | In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible |
| CVE-2026-2225 | CRITICAL | 9.8 | 0.4% | Feb 9, 2026 | A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admi... |
| CVE-2026-2234 | CRITICAL | 9.3 | 0.4% | Feb 9, 2026 | C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to rea... |
| CVE-2026-2223 | CRITICAL | 9.8 | 0.4% | Feb 9, 2026 | A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some u... |
| CVE-2026-22906 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining ... |
| CVE-2026-22904 | CRITICAL | 9.8 | 0.5% | Feb 9, 2026 | Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attack... |
| CVE-2026-22903 | CRITICAL | 9.8 | 0.7% | Feb 9, 2026 | An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can ... |
| CVE-2026-2221 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the ... |
| CVE-2026-2220 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file... |
| CVE-2026-1868 | CRITICAL | 9.9 | 0.5% | Feb 9, 2026 | GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions ... |
| CVE-2026-2217 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of th... |
| CVE-2026-1615 | CRITICAL | 9.8 | 1.0% | Feb 9, 2026 | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-s... |
| CVE-2026-2212 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown func... |
| CVE-2026-2211 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Admi... |
| CVE-2026-2199 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown func... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now