2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28556 | MEDIUM | 5.4 | 0.2% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,... |
| CVE-2026-28555 | MEDIUM | 5.3 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo... |
| CVE-2026-28554 | MEDIUM | 5.3 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u... |
| CVE-2026-3010 | MEDIUM | 6.1 | 0.2% | Feb 28, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2026-1542 | MEDIUM | 6.5 | 0.2% | Feb 28, 2026 | The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated... |
| CVE-2026-28426 | MEDIUM | 5.4 | 0.3% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS ... |
| CVE-2026-28424 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email ... |
| CVE-2026-27759 | MEDIUM | 5.3 | 0.2% | Feb 27, 2026 | Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticate... |
| CVE-2026-28420 | MEDIUM | 4.4 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou... |
| CVE-2026-28419 | MEDIUM | 6.6 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'... |
| CVE-2026-28418 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r... |
| CVE-2026-28415 | MEDIUM | 4.7 | 0.2% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(... |
| CVE-2026-28407 | MEDIUM | 5.3 | 0.2% | Feb 27, 2026 | malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior ... |
| CVE-2026-27167 | MEDIUM | 5.9 | 0.5% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version ... |
| CVE-2026-28352 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers... |
| CVE-2026-28351 | MEDIUM | 5.3 | 0.4% | Feb 27, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability... |
| CVE-2026-28338 | MEDIUM | 6.1 | 0.3% | Feb 27, 2026 | PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for... |
| CVE-2026-28288 | MEDIUM | 5.3 | 0.6% | Feb 27, 2026 | Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi... |
| CVE-2026-28272 | MEDIUM | 4.8 | 0.3% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway... |
| CVE-2026-28271 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional... |
| CVE-2026-3255 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP... |
| CVE-2026-28354 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne... |
| CVE-2026-27824 | MEDIUM | 5.3 | 0.1% | Feb 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-27810 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-27793 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now