2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27792 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner... |
| CVE-2026-27734 | MEDIUM | 6.5 | 0.5% | Feb 27, 2026 | Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c... |
| CVE-2026-26997 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can stor... |
| CVE-2026-27758 | MEDIUM | 6.5 | 0.1% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man... |
| CVE-2026-27756 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the... |
| CVE-2026-27754 | MEDIUM | 6.9 | 0.1% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio... |
| CVE-2026-22716 | MEDIUM | 5 | 0.2% | Feb 27, 2026 | Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administr... |
| CVE-2026-27753 | MEDIUM | 6.9 | 0.3% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re... |
| CVE-2026-24488 | MEDIUM | 6.5 | 0.4% | Feb 27, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ... |
| CVE-2026-3277 | MEDIUM | 6.5 | 0.2% | Feb 27, 2026 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s... |
| CVE-2026-3327 | MEDIUM | 4.8 | 0.3% | Feb 27, 2026 | Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated use... |
| CVE-2026-2831 | MEDIUM | 4.9 | 0.3% | Feb 27, 2026 | The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, an... |
| CVE-2026-24351 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can injec... |
| CVE-2026-24350 | MEDIUM | 5.4 | 0.2% | Feb 27, 2026 | PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file... |
| CVE-2026-1434 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opene... |
| CVE-2026-1305 | MEDIUM | 5.3 | 0.4% | Feb 27, 2026 | The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu... |
| CVE-2026-2383 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve... |
| CVE-2026-2362 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute... |
| CVE-2026-0871 | MEDIUM | 4.9 | 0.3% | Feb 27, 2026 | A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can vi... |
| CVE-2026-3302 | MEDIUM | 6.1 | 0.4% | Feb 27, 2026 | A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f... |
| CVE-2026-3293 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner ... |
| CVE-2026-27653 | MEDIUM | 6.7 | 0.1% | Feb 27, 2026 | The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission... |
| CVE-2026-1558 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, ... |
| CVE-2026-3286 | MEDIUM | 4.3 | 0.3% | Feb 27, 2026 | A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save ... |
| CVE-2026-3284 | MEDIUM | 5.5 | 0.2% | Feb 27, 2026 | A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conver... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now