2026 CVE Vulnerabilities
70,492 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21659 | CRITICAL | 9.8 | 0.9% | Feb 27, 2026 | Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John... |
| CVE-2026-1305 | MEDIUM | 5.3 | 0.4% | Feb 27, 2026 | The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu... |
| CVE-2026-2383 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve... |
| CVE-2026-2362 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute... |
| CVE-2026-2252 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft... |
| CVE-2026-2251 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows... |
| CVE-2026-21658 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh... |
| CVE-2026-21657 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al... |
| CVE-2026-21656 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al... |
| CVE-2026-21654 | CRITICAL | 9.8 | 1.5% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont... |
| CVE-2026-1627 | HIGH | 8.1 | 0.2% | Feb 27, 2026 | An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromis... |
| CVE-2026-1626 | CRITICAL | 9.1 | 0.2% | Feb 27, 2026 | An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma... |
| CVE-2026-27776 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only... |
| CVE-2026-0980 | HIGH | 8.8 | 0.8% | Feb 27, 2026 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An... |
| CVE-2026-0871 | MEDIUM | 4.9 | 0.3% | Feb 27, 2026 | A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can vi... |
| CVE-2026-3302 | MEDIUM | 6.1 | 0.4% | Feb 27, 2026 | A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f... |
| CVE-2026-3301 | CRITICAL | 9.8 | 4.0% | Feb 27, 2026 | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi... |
| CVE-2026-3293 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner ... |
| CVE-2026-28372 | HIGH | 7.8 | 0.4% | Feb 27, 2026 | telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden... |
| CVE-2026-27653 | MEDIUM | 6.7 | 0.1% | Feb 27, 2026 | The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission... |
| CVE-2026-3292 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph... |
| CVE-2026-3289 | CRITICAL | 9.8 | 0.7% | Feb 27, 2026 | A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file Templ... |
| CVE-2026-3287 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the... |
| CVE-2026-28370 | CRITICAL | 9.1 | 0.8% | Feb 27, 2026 | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage... |
| CVE-2026-1558 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now