2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1831 | LOW | 2.7 | 0.3% | Feb 18, 2026 | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac... |
| CVE-2026-2642 | LOW | 3.3 | 0.2% | Feb 18, 2026 | A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the functi... |
| CVE-2026-2641 | LOW | 3.3 | 0.2% | Feb 18, 2026 | A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpressio... |
| CVE-2026-0102 | LOW | 3.1 | 0.5% | Feb 17, 2026 | Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially w... |
| CVE-2026-24733 | LOW | 3.7 | 0.5% | Feb 17, 2026 | Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If... |
| CVE-2026-20796 | LOW | 3.1 | 0.2% | Feb 13, 2026 | Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which ... |
| CVE-2026-0872 | LOW | 2.5 | 0.2% | Feb 13, 2026 | Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoo... |
| CVE-2026-20681 | LOW | 3.3 | 0.1% | Feb 11, 2026 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 2... |
| CVE-2026-20671 | LOW | 3.1 | 0.3% | Feb 11, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPad... |
| CVE-2026-20663 | LOW | 3.3 | 0.1% | Feb 11, 2026 | The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 2... |
| CVE-2026-20656 | LOW | 3.3 | 0.1% | Feb 11, 2026 | A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, ... |
| CVE-2026-20646 | LOW | 3.3 | 0.1% | Feb 11, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may... |
| CVE-2026-20642 | LOW | 2.4 | 0.1% | Feb 11, 2026 | An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access ... |
| CVE-2026-20601 | LOW | 3.3 | 0.1% | Feb 11, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be a... |
| CVE-2026-0228 | LOW | 1.3 | 0.2% | Feb 11, 2026 | An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to ... |
| CVE-2026-2345 | LOW | 3.6 | 0.1% | Feb 11, 2026 | Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add... |
| CVE-2026-26013 | LOW | 3.7 | 0.4% | Feb 10, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_token... |
| CVE-2026-1762 | LOW | 2.9 | 0.2% | Feb 10, 2026 | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a... |
| CVE-2026-21249 | LOW | 3.3 | 11.4% | Feb 10, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-23901 | LOW | 2.5 | 0.2% | Feb 10, 2026 | Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.... |
| CVE-2026-24320 | LOW | 3.1 | 0.2% | Feb 10, 2026 | Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke... |
| CVE-2026-23686 | LOW | 3.4 | 0.2% | Feb 10, 2026 | Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr... |
| CVE-2026-2246 | LOW | 3.3 | 0.2% | Feb 9, 2026 | A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the ... |
| CVE-2026-2245 | LOW | 3.3 | 0.1% | Feb 9, 2026 | A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library sr... |
| CVE-2026-2215 | LOW | 3.7 | 0.3% | Feb 9, 2026 | A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now