2026 CVE Vulnerabilities
70,478 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28352 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers... |
| CVE-2026-28351 | MEDIUM | 5.3 | 0.4% | Feb 27, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability... |
| CVE-2026-28338 | MEDIUM | 6.1 | 0.3% | Feb 27, 2026 | PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for... |
| CVE-2026-28288 | MEDIUM | 5.3 | 0.6% | Feb 27, 2026 | Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi... |
| CVE-2026-28272 | MEDIUM | 4.8 | 0.3% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway... |
| CVE-2026-28271 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional... |
| CVE-2026-28270 | HIGH | 7.2 | 1.6% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl... |
| CVE-2026-28268 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil... |
| CVE-2026-3255 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP... |
| CVE-2026-28354 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne... |
| CVE-2026-28231 | CRITICAL | 9.1 | 0.6% | Feb 27, 2026 | pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer o... |
| CVE-2026-27947 | HIGH | 8.8 | 0.7% | Feb 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an... |
| CVE-2026-27836 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p... |
| CVE-2026-27832 | HIGH | 8.8 | 0.2% | Feb 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, an... |
| CVE-2026-27824 | MEDIUM | 5.3 | 0.1% | Feb 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-27810 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-27793 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G... |
| CVE-2026-27792 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner... |
| CVE-2026-27734 | MEDIUM | 6.5 | 0.5% | Feb 27, 2026 | Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c... |
| CVE-2026-27707 | CRITICAL | 9.8 | 0.5% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and ... |
| CVE-2026-27583 | — | — | — | Feb 27, 2026 | Rejected reason: Further research determined the situation described is not a vulnerability. |
| CVE-2026-27582 | — | — | — | Feb 27, 2026 | Rejected reason: Further research determined the situation described is not a vulnerability. |
| CVE-2026-27581 | — | — | — | Feb 27, 2026 | Rejected reason: Further research determined the situation described is not a vulnerability. |
| CVE-2026-27580 | — | — | — | Feb 27, 2026 | Rejected reason: Further research determined the situation described is not a vulnerability. |
| CVE-2026-27573 | — | — | — | Feb 27, 2026 | Rejected reason: Further research determined the situation described is not a vulnerability. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now