2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2974 | LOW | 2.5 | 0.1% | Feb 23, 2026 | A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of... |
| CVE-2026-2968 | LOW | 3.7 | 0.2% | Feb 23, 2026 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of t... |
| CVE-2026-2967 | LOW | 3.7 | 0.5% | Feb 23, 2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file... |
| CVE-2026-2966 | LOW | 3.7 | 0.4% | Feb 23, 2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the ... |
| CVE-2026-2965 | LOW | 2.4 | 0.2% | Feb 23, 2026 | A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown ... |
| CVE-2026-2903 | LOW | 3.3 | 0.1% | Feb 22, 2026 | A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src... |
| CVE-2026-2889 | LOW | 3.3 | 0.1% | Feb 21, 2026 | A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx... |
| CVE-2026-27467 | LOW | 2.4 | 0.2% | Feb 21, 2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the m... |
| CVE-2026-22885 | LOW | 3.7 | 0.4% | Feb 20, 2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th... |
| CVE-2026-21620 | LOW | 2.3 | 0.5% | Feb 20, 2026 | Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file mo... |
| CVE-2026-2825 | LOW | 3.5 | 0.2% | Feb 20, 2026 | A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file t... |
| CVE-2026-27007 | LOW | 3.3 | 0.2% | Feb 20, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.2.15, `normalizeForHash` in `src/agents/sandbox/config-hash.t... |
| CVE-2026-26964 | LOW | 2.7 | 0.3% | Feb 20, 2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.63... |
| CVE-2026-26958 | LOW | 1.7 | 0.4% | Feb 19, 2026 | filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographi... |
| CVE-2026-24122 | LOW | 3.7 | 0.2% | Feb 19, 2026 | Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certi... |
| CVE-2026-25423 | LOW | 3.8 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting ... |
| CVE-2026-2733 | LOW | 3.8 | 0.3% | Feb 19, 2026 | A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even afte... |
| CVE-2026-2709 | LOW | 3.5 | 0.3% | Feb 19, 2026 | A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-mast... |
| CVE-2026-2702 | LOW | 3.1 | 0.3% | Feb 19, 2026 | A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the c... |
| CVE-2026-25120 | LOW | 2.7 | 0.3% | Feb 19, 2026 | Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that... |
| CVE-2026-24764 | LOW | 3.7 | 0.2% | Feb 19, 2026 | OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, ... |
| CVE-2026-2656 | LOW | 2.5 | 0.2% | Feb 18, 2026 | A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file... |
| CVE-2026-2655 | LOW | 2.5 | 0.2% | Feb 18, 2026 | A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::opera... |
| CVE-2026-1582 | LOW | 3.7 | 0.3% | Feb 18, 2026 | The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2026-2419 | LOW | 2.7 | 0.7% | Feb 18, 2026 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now