2026 CVE Vulnerabilities
46,924 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2114 | CRITICAL | 9.8 | 0.4% | Feb 7, 2026 | A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of t... |
| CVE-2026-25858 | CRITICAL | 9.3 | 0.6% | Feb 7, 2026 | macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workf... |
| CVE-2026-25560 | CRITICAL | 9.8 | 0.7% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna... |
| CVE-2026-2113 | CRITICAL | 9.8 | 0.6% | Feb 7, 2026 | A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library... |
| CVE-2026-2090 | CRITICAL | 9.8 | 0.3% | Feb 7, 2026 | A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown process... |
| CVE-2026-2089 | CRITICAL | 9.8 | 0.3% | Feb 7, 2026 | A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of t... |
| CVE-2026-2088 | CRITICAL | 9.8 | 0.4% | Feb 7, 2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the f... |
| CVE-2026-2087 | CRITICAL | 9.8 | 0.3% | Feb 7, 2026 | A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functiona... |
| CVE-2026-2083 | CRITICAL | 9.8 | 0.3% | Feb 7, 2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the... |
| CVE-2026-2073 | CRITICAL | 9.8 | 0.3% | Feb 7, 2026 | A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil... |
| CVE-2026-25804 | CRITICAL | 9.1 | 0.4% | Feb 6, 2026 | Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's... |
| CVE-2026-25803 | CRITICAL | 9.8 | 0.4% | Feb 6, 2026 | 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an admi... |
| CVE-2026-25763 | CRITICAL | 9.9 | 0.5% | Feb 6, 2026 | OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary ... |
| CVE-2026-25544 | CRITICAL | 9.8 | 0.5% | Feb 6, 2026 | Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fi... |
| CVE-2026-1731 | CRITICAL | 9.8 | 86.1% | Feb 6, 2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-auth... |
| CVE-2026-1727 | CRITICAL | 9.1 | 0.3% | Feb 6, 2026 | The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable ... |
| CVE-2026-25632 | CRITICAL | 10 | 0.7% | Feb 6, 2026 | EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis... |
| CVE-2026-25592 | CRITICAL | 9.9 | 1.9% | Feb 6, 2026 | Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an ... |
| CVE-2026-25643 | CRITICAL | 9.1 | 2.9% | Feb 6, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critic... |
| CVE-2026-25641 | CRITICAL | 9 | 0.5% | Feb 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch... |
| CVE-2026-25587 | CRITICAL | 10 | 0.6% | Feb 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtain... |
| CVE-2026-25586 | CRITICAL | 10 | 0.6% | Feb 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty ... |
| CVE-2026-25520 | CRITICAL | 10 | 0.8% | Feb 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.val... |
| CVE-2026-1709 | CRITICAL | 9.8 | 5.4% | Feb 6, 2026 | A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer S... |
| CVE-2026-25753 | CRITICAL | 9.8 | 0.4% | Feb 6, 2026 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now