2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25220 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24908 | MEDIUM | 6.5 | 0.5% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24890 | MEDIUM | 6.5 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24487 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-27794 | MEDIUM | 6.6 | 0.7% | Feb 25, 2026 | LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu... |
| CVE-2026-27738 | MEDIUM | 6.9 | 0.3% | Feb 25, 2026 | The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the i... |
| CVE-2026-27736 | MEDIUM | 6.1 | 0.1% | Feb 25, 2026 | BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received wi... |
| CVE-2026-27705 | MEDIUM | 6.5 | 0.2% | Feb 25, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in... |
| CVE-2026-26717 | MEDIUM | 4.8 | 0.4% | Feb 25, 2026 | An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operat... |
| CVE-2026-20122 | MEDIUM | 5.4 | 7.0% | Feb 25, 2026 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite a... |
| CVE-2026-20107 | MEDIUM | 5.5 | 0.1% | Feb 25, 2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could all... |
| CVE-2026-20099 | MEDIUM | 6.7 | 0.6% | Feb 25, 2026 | A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could a... |
| CVE-2026-20091 | MEDIUM | 4.8 | 0.2% | Feb 25, 2026 | A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow ... |
| CVE-2026-20037 | MEDIUM | 4.4 | 0.1% | Feb 25, 2026 | A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local atta... |
| CVE-2026-20036 | MEDIUM | 6.5 | 0.4% | Feb 25, 2026 | A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated... |
| CVE-2026-3188 | MEDIUM | 4.3 | 0.3% | Feb 25, 2026 | A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the... |
| CVE-2026-27846 | MEDIUM | 6.2 | 0.1% | Feb 25, 2026 | Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a ... |
| CVE-2026-2878 | MEDIUM | 5.9 | 0.2% | Feb 25, 2026 | In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyn... |
| CVE-2026-27695 | MEDIUM | 5.3 | 0.2% | Feb 25, 2026 | zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets... |
| CVE-2026-27691 | MEDIUM | 5.5 | 0.2% | Feb 25, 2026 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu... |
| CVE-2026-3186 | MEDIUM | 4.3 | 0.2% | Feb 25, 2026 | A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unk... |
| CVE-2026-3185 | MEDIUM | 5.5 | 0.4% | Feb 25, 2026 | A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /... |
| CVE-2026-28195 | MEDIUM | 4.3 | 0.2% | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build confi... |
| CVE-2026-28194 | MEDIUM | 6.1 | 0.2% | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |
| CVE-2026-28193 | MEDIUM | 5.3 | 0.2% | Feb 25, 2026 | In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now