2026 CVE Vulnerabilities
70,490 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27753 | MEDIUM | 6.9 | 0.3% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re... |
| CVE-2026-27752 | HIGH | 8.2 | 0.2% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al... |
| CVE-2026-27751 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot... |
| CVE-2026-26862 | HIGH | 8.3 | 0.4% | Feb 27, 2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag... |
| CVE-2026-26861 | HIGH | 8.3 | 0.2% | Feb 27, 2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han... |
| CVE-2026-21619 | HIGH | 7.5 | 0.6% | Feb 27, 2026 | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), ... |
| CVE-2026-2293 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fas... |
| CVE-2026-25147 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24488 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ... |
| CVE-2026-3304 | HIGH | 7.5 | 0.7% | Feb 27, 2026 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo... |
| CVE-2026-3277 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s... |
| CVE-2026-2750 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tick... |
| CVE-2026-2749 | HIGH | 8.8 | 0.5% | Feb 27, 2026 | Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue aff... |
| CVE-2026-2359 | HIGH | 7.5 | 0.7% | Feb 27, 2026 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo... |
| CVE-2026-3327 | MEDIUM | 4.8 | 0.3% | Feb 27, 2026 | Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated use... |
| CVE-2026-3223 | HIGH | 7.8 | 0.1% | Feb 27, 2026 | Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. |
| CVE-2026-2751 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web ... |
| CVE-2026-2831 | MEDIUM | 4.9 | 0.3% | Feb 27, 2026 | The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, an... |
| CVE-2026-24352 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa... |
| CVE-2026-24351 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can injec... |
| CVE-2026-24350 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file... |
| CVE-2026-1434 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opene... |
| CVE-2026-21660 | CRITICAL | 9.8 | 0.2% | Feb 27, 2026 | A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in... |
| CVE-2026-21659 | CRITICAL | 9.8 | 0.9% | Feb 27, 2026 | Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John... |
| CVE-2026-1305 | MEDIUM | 5.3 | 0.4% | Feb 27, 2026 | The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now