2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3449 | LOW | 3.3 | 0.1% | Mar 3, 2026 | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resol... |
| CVE-2026-20757 | LOW | 2.5 | 0.1% | Mar 3, 2026 | Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited... |
| CVE-2026-0995 | LOW | 3.6 | 0.1% | Mar 2, 2026 | An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to... |
| CVE-2026-3407 | LOW | 3.3 | 0.1% | Mar 2, 2026 | A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the fi... |
| CVE-2026-28422 | LOW | 2.2 | 0.1% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl... |
| CVE-2026-28355 | LOW | 1.3 | 0.4% | Feb 27, 2026 | Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Script... |
| CVE-2026-22717 | LOW | 2.7 | 0.2% | Feb 27, 2026 | Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administra... |
| CVE-2026-27838 | LOW | 3.5 | 0.2% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calli... |
| CVE-2026-28227 | LOW | 2.7 | 3.1% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publ... |
| CVE-2026-27153 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could e... |
| CVE-2026-27152 | LOW | 3.8 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-p... |
| CVE-2026-27151 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` a... |
| CVE-2026-27150 | LOW | 3.8 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_... |
| CVE-2026-26979 | LOW | 2.7 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able... |
| CVE-2026-23749 | LOW | 2.9 | 0.2% | Feb 26, 2026 | Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to impr... |
| CVE-2026-3193 | LOW | 3.1 | 0.2% | Feb 25, 2026 | A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. Th... |
| CVE-2026-3189 | LOW | 3.1 | 0.2% | Feb 25, 2026 | A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code ... |
| CVE-2026-3206 | LOW | 1.3 | 0.3% | Feb 25, 2026 | Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU Kr... |
| CVE-2026-28196 | LOW | 2.3 | 0.1% | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
| CVE-2026-21725 | LOW | 2 | 0.2% | Feb 25, 2026 | A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w... |
| CVE-2026-27632 | LOW | 3.1 | 0.1% | Feb 25, 2026 | Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar a... |
| CVE-2026-23859 | LOW | 2.7 | 0.3% | Feb 24, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnera... |
| CVE-2026-3041 | LOW | 2.4 | 0.3% | Feb 23, 2026 | A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the f... |
| CVE-2026-22568 | LOW | 2.7 | 0.2% | Feb 23, 2026 | Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated ... |
| CVE-2026-22567 | LOW | 2.7 | 0.2% | Feb 23, 2026 | Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate ba... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now