2026 CVE Vulnerabilities
70,492 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1442 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a... |
| CVE-2026-3286 | MEDIUM | 4.3 | 0.3% | Feb 27, 2026 | A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save ... |
| CVE-2026-2428 | HIGH | 7.5 | 0.1% | Feb 27, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in... |
| CVE-2026-28364 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re... |
| CVE-2026-28363 | HIGH | 8.8 | 0.5% | Feb 27, 2026 | In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation... |
| CVE-2026-3285 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the ... |
| CVE-2026-3284 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conver... |
| CVE-2026-3283 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file li... |
| CVE-2026-3282 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file li... |
| CVE-2026-3281 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conver... |
| CVE-2026-3275 | HIGH | 8.8 | 0.8% | Feb 27, 2026 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre... |
| CVE-2026-3274 | HIGH | 8.8 | 0.9% | Feb 27, 2026 | A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f... |
| CVE-2026-3037 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t... |
| CVE-2026-25721 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25196 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-25105 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta... |
| CVE-2026-25037 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-24498 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network... |
| CVE-2026-24497 | CRITICAL | 9.8 | 0.3% | Feb 27, 2026 | Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue aff... |
| CVE-2026-24452 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker... |
| CVE-2026-23702 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-22877 | CRITICAL | 9.1 | 0.6% | Feb 27, 2026 | An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to... |
| CVE-2026-20797 | CRITICAL | 9.8 | 0.8% | Feb 27, 2026 | A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated att... |
| CVE-2026-20764 | HIGH | 8.8 | 1.9% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker ... |
| CVE-2026-3273 | HIGH | 8.8 | 0.6% | Feb 27, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now