2026 CVE Vulnerabilities
46,941 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25139 | CRITICAL | 9.1 | 0.5% | Feb 4, 2026 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2026-22247 | CRITICAL | 9.1 | 0.3% | Feb 4, 2026 | GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can ... |
| CVE-2026-25115 | CRITICAL | 9.9 | 0.5% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allo... |
| CVE-2026-25053 | CRITICAL | 9.9 | 0.6% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git nod... |
| CVE-2026-25052 | CRITICAL | 9.9 | 0.3% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file ac... |
| CVE-2026-25049 | CRITICAL | 9.9 | 1.2% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with per... |
| CVE-2026-1813 | CRITICAL | 9.8 | 0.3% | Feb 4, 2026 | A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/... |
| CVE-2026-1633 | CRITICAL | 10 | 0.5% | Feb 4, 2026 | The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authe... |
| CVE-2026-1812 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the fi... |
| CVE-2026-1632 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, ... |
| CVE-2026-25150 | CRITICAL | 10 | 0.6% | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists ... |
| CVE-2026-1341 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. |
| CVE-2026-25241 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL... |
| CVE-2026-25240 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner... |
| CVE-2026-25238 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner... |
| CVE-2026-25237 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() ... |
| CVE-2026-25236 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk e... |
| CVE-2026-25234 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner... |
| CVE-2026-25233 | CRITICAL | 9.1 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadm... |
| CVE-2026-1568 | CRITICAL | 9.6 | 0.1% | Feb 3, 2026 | Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c... |
| CVE-2026-1432 | CRITICAL | 9.3 | 0.3% | Feb 3, 2026 | SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vuln... |
| CVE-2026-24465 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead ... |
| CVE-2026-24936 | CRITICAL | 9.8 | 0.8% | Feb 3, 2026 | When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerab... |
| CVE-2026-25142 | CRITICAL | 10 | 1.1% | Feb 2, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ whic... |
| CVE-2026-25137 | CRITICAL | 9.1 | 10.1% | Feb 2, 2026 | The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now