2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25774 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-25195 | MEDIUM | 6.6 | 1.4% | Feb 27, 2026 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack... |
| CVE-2026-22878 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-3269 | MEDIUM | 6.5 | 0.6% | Feb 27, 2026 | A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of ... |
| CVE-2026-27773 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-22890 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-20733 | MEDIUM | 5.3 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-3268 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file... |
| CVE-2026-28230 | MEDIUM | 6.3 | 0.2% | Feb 26, 2026 | SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger se... |
| CVE-2026-28226 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL in... |
| CVE-2026-28225 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-28217 | MEDIUM | 6.5 | 0.4% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac... |
| CVE-2026-28208 | MEDIUM | 5.9 | 12.0% | Feb 26, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `... |
| CVE-2026-27839 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`... |
| CVE-2026-28219 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author... |
| CVE-2026-28218 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access c... |
| CVE-2026-27835 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`... |
| CVE-2026-27457 | MEDIUM | 4.3 | 0.3% | Feb 26, 2026 | Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`... |
| CVE-2026-27154 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name c... |
| CVE-2026-27162 | MEDIUM | 4.9 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was... |
| CVE-2026-27149 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in P... |
| CVE-2026-27021 | MEDIUM | 5.3 | 0.3% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoin... |
| CVE-2026-26973 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec... |
| CVE-2026-22722 | MEDIUM | 6.1 | 0.1% | Feb 26, 2026 | A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null poi... |
| CVE-2026-22715 | MEDIUM | 5.9 | 0.2% | Feb 26, 2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now