2026 CVE Vulnerabilities
70,494 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28276 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p... |
| CVE-2026-28275 | HIGH | 8.1 | 0.4% | Feb 26, 2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p... |
| CVE-2026-28274 | HIGH | 8.7 | 0.6% | Feb 26, 2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S... |
| CVE-2026-28269 | HIGH | 8.8 | 2.0% | Feb 26, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio... |
| CVE-2026-28230 | MEDIUM | 6.3 | 0.2% | Feb 26, 2026 | SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger se... |
| CVE-2026-28226 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL in... |
| CVE-2026-28225 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-28217 | MEDIUM | 6.5 | 0.4% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac... |
| CVE-2026-28216 | HIGH | 8.3 | 0.4% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o... |
| CVE-2026-28215 | CRITICAL | 9.1 | 0.5% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw... |
| CVE-2026-28213 | CRITICAL | 9.8 | 0.4% | Feb 26, 2026 | EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password"... |
| CVE-2026-28211 | HIGH | 7.8 | 0.2% | Feb 26, 2026 | The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability ... |
| CVE-2026-28208 | MEDIUM | 5.9 | 12.0% | Feb 26, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `... |
| CVE-2026-28207 | HIGH | 7.3 | 0.9% | Feb 26, 2026 | Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command inj... |
| CVE-2026-27839 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`... |
| CVE-2026-27838 | LOW | 3.5 | 0.2% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calli... |
| CVE-2026-27638 | HIGH | 7.1 | 0.3% | Feb 26, 2026 | Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi... |
| CVE-2026-3263 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this... |
| CVE-2026-3262 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is... |
| CVE-2026-3261 | CRITICAL | 9.8 | 0.3% | Feb 26, 2026 | A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin... |
| CVE-2026-28227 | LOW | 2.7 | 3.1% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publ... |
| CVE-2026-28219 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author... |
| CVE-2026-28218 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access c... |
| CVE-2026-27835 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`... |
| CVE-2026-27457 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now