2026 CVE Vulnerabilities
70,478 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28515 | HIGH | 8.8 | 1.2% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and conta... |
| CVE-2026-28426 | MEDIUM | 5.4 | 0.3% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS ... |
| CVE-2026-28425 | HIGH | 8 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenti... |
| CVE-2026-28424 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email ... |
| CVE-2026-28423 | HIGH | 8.6 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide ... |
| CVE-2026-27759 | MEDIUM | 5.3 | 0.2% | Feb 27, 2026 | Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticate... |
| CVE-2026-28422 | LOW | 2.2 | 0.1% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl... |
| CVE-2026-28421 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati... |
| CVE-2026-28420 | MEDIUM | 4.4 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou... |
| CVE-2026-28419 | MEDIUM | 6.6 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'... |
| CVE-2026-28418 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r... |
| CVE-2026-28417 | HIGH | 7.8 | 1.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists... |
| CVE-2026-28416 | HIGH | 8.6 | 0.3% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo... |
| CVE-2026-28415 | MEDIUM | 4.7 | 0.2% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(... |
| CVE-2026-28414 | HIGH | 7.5 | 3.1% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win... |
| CVE-2026-28411 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on... |
| CVE-2026-28409 | HIGH | 7.2 | 3.3% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne... |
| CVE-2026-28408 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.p... |
| CVE-2026-28407 | MEDIUM | 5.3 | 0.2% | Feb 27, 2026 | malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior ... |
| CVE-2026-28406 | HIGH | 8.2 | 0.6% | Feb 27, 2026 | kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers... |
| CVE-2026-28402 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-28400 | HIGH | 7.5 | 0.2% | Feb 27, 2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e... |
| CVE-2026-27939 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6... |
| CVE-2026-27167 | MEDIUM | 5.9 | 0.5% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version ... |
| CVE-2026-28355 | LOW | 1.3 | 0.4% | Feb 27, 2026 | Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Script... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now