2026 CVE Vulnerabilities
70,496 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27835 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`... |
| CVE-2026-27457 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`... |
| CVE-2026-27449 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi... |
| CVE-2026-27154 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name c... |
| CVE-2026-27153 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could e... |
| CVE-2026-25741 | HIGH | 7.1 | 0.3% | Feb 26, 2026 | Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo... |
| CVE-2026-27162 | MEDIUM | 4.9 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was... |
| CVE-2026-27152 | LOW | 3.8 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-p... |
| CVE-2026-27151 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` a... |
| CVE-2026-27150 | LOW | 3.8 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_... |
| CVE-2026-27149 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in P... |
| CVE-2026-27021 | MEDIUM | 5.3 | 0.3% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoin... |
| CVE-2026-22207 | CRITICAL | 9.8 | 0.4% | Feb 26, 2026 | OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u... |
| CVE-2026-22206 | HIGH | 8.8 | 0.6% | Feb 26, 2026 | SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to exe... |
| CVE-2026-22205 | HIGH | 8.7 | 0.5% | Feb 26, 2026 | SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una... |
| CVE-2026-27510 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg... |
| CVE-2026-27509 | HIGH | 8.5 | 0.5% | Feb 26, 2026 | Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat... |
| CVE-2026-27141 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic |
| CVE-2026-26979 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able... |
| CVE-2026-26973 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec... |
| CVE-2026-23939 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix... |
| CVE-2026-1565 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-1241 | HIGH | 8.7 | 0.3% | Feb 26, 2026 | The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage... |
| CVE-2026-26938 | HIGH | 7.7 | 0.3% | Feb 26, 2026 | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou... |
| CVE-2026-26937 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now