2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27465 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration A... |
| CVE-2026-25963 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s ce... |
| CVE-2026-24004 | MEDIUM | 5.3 | 0.3% | Feb 26, 2026 | Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub... |
| CVE-2026-23999 | MEDIUM | 5.5 | 0.1% | Feb 26, 2026 | Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs ... |
| CVE-2026-2506 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin... |
| CVE-2026-2499 | MEDIUM | 4.4 | 0.2% | Feb 26, 2026 | The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2026-2498 | MEDIUM | 4.4 | 0.2% | Feb 26, 2026 | The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2026-2489 | MEDIUM | 4.4 | 0.2% | Feb 26, 2026 | The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea ... |
| CVE-2026-2029 | MEDIUM | 6.4 | 0.2% | Feb 26, 2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_... |
| CVE-2026-27973 | MEDIUM | 4.8 | 0.2% | Feb 26, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i... |
| CVE-2026-27970 | MEDIUM | 6.1 | 0.5% | Feb 26, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-27968 | MEDIUM | 4.3 | 0.2% | Feb 26, 2026 | Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep... |
| CVE-2026-27954 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52,... |
| CVE-2026-27948 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via U... |
| CVE-2026-27943 | MEDIUM | 6.5 | 0.3% | Feb 26, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ... |
| CVE-2026-27902 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly esca... |
| CVE-2026-27901 | MEDIUM | 6.1 | 0.2% | Feb 26, 2026 | Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textConte... |
| CVE-2026-27887 | MEDIUM | 6.9 | 0.2% | Feb 26, 2026 | Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin... |
| CVE-2026-22728 | MEDIUM | 4.9 | 0.4% | Feb 26, 2026 | Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotati... |
| CVE-2026-27946 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's... |
| CVE-2026-27945 | MEDIUM | 6.5 | 0.2% | Feb 26, 2026 | ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta i... |
| CVE-2026-27884 | MEDIUM | 5.3 | 0.3% | Feb 26, 2026 | NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file a... |
| CVE-2026-27840 | MEDIUM | 4.3 | 0.1% | Feb 26, 2026 | ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.... |
| CVE-2026-27933 | MEDIUM | 6.8 | 0.3% | Feb 26, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-27799 | MEDIUM | 4.4 | 0.1% | Feb 26, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now