2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26934 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-on... |
| CVE-2026-26227 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature du... |
| CVE-2026-23748 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB ... |
| CVE-2026-23747 | MEDIUM | 6.3 | 0.3% | Feb 26, 2026 | Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in P... |
| CVE-2026-28296 | MEDIUM | 4.3 | 0.4% | Feb 26, 2026 | A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi... |
| CVE-2026-28295 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar... |
| CVE-2026-26228 | MEDIUM | 4.9 | 0.3% | Feb 26, 2026 | VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout... |
| CVE-2026-26207 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy`... |
| CVE-2026-26077 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en... |
| CVE-2026-2680 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.... |
| CVE-2026-2679 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolte... |
| CVE-2026-2678 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura... |
| CVE-2026-2677 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer... |
| CVE-2026-28132 | MEDIUM | 5.3 | 0.2% | Feb 26, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Ph... |
| CVE-2026-28131 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-e... |
| CVE-2026-28083 | MEDIUM | 6.5 | 0.1% | Feb 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome... |
| CVE-2026-1698 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 throu... |
| CVE-2026-1697 | MEDIUM | 6.5 | 0.1% | Feb 26, 2026 | The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in versio... |
| CVE-2026-1696 | MEDIUM | 6.1 | 0.1% | Feb 26, 2026 | Some HTTP security headers are not properly set by the web server when sending responses to the client application. |
| CVE-2026-1695 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of P... |
| CVE-2026-1694 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of t... |
| CVE-2026-1692 | MEDIUM | 6.1 | 0.1% | Feb 26, 2026 | A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebSc... |
| CVE-2026-2356 | MEDIUM | 5.3 | 0.2% | Feb 26, 2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln... |
| CVE-2026-27974 | MEDIUM | 4.8 | 0.2% | Feb 26, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versi... |
| CVE-2026-27963 | MEDIUM | 4.8 | 0.2% | Feb 26, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now