2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3118 | MEDIUM | 6.5 | 0.5% | Feb 25, 2026 | A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to ... |
| CVE-2026-26104 | MEDIUM | 5.5 | 0.1% | Feb 25, 2026 | A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption heade... |
| CVE-2026-2410 | MEDIUM | 4.3 | 0.1% | Feb 25, 2026 | The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forger... |
| CVE-2026-2367 | MEDIUM | 6.4 | 0.2% | Feb 25, 2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-2301 | MEDIUM | 4.3 | 0.2% | Feb 25, 2026 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve... |
| CVE-2026-3171 | MEDIUM | 5.4 | 0.2% | Feb 25, 2026 | A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi... |
| CVE-2026-2479 | MEDIUM | 5 | 0.2% | Feb 25, 2026 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t... |
| CVE-2026-3170 | MEDIUM | 4.8 | 0.2% | Feb 25, 2026 | A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected... |
| CVE-2026-1614 | MEDIUM | 6.4 | 0.2% | Feb 25, 2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-3100 | MEDIUM | 6.5 | 0.2% | Feb 25, 2026 | The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP ser... |
| CVE-2026-27645 | MEDIUM | 6.1 | 0.4% | Feb 25, 2026 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-wat... |
| CVE-2026-27624 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and... |
| CVE-2026-27746 | MEDIUM | 6.1 | 0.2% | Feb 25, 2026 | The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_pro... |
| CVE-2026-27639 | MEDIUM | 5.4 | 0.3% | Feb 25, 2026 | Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Script... |
| CVE-2026-27627 | MEDIUM | 6.1 | 0.3% | Feb 25, 2026 | Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `reada... |
| CVE-2026-3146 | MEDIUM | 5.5 | 0.2% | Feb 25, 2026 | A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_he... |
| CVE-2026-27822 | MEDIUM | 5.4 | 6.0% | Feb 25, 2026 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Script... |
| CVE-2026-27621 | MEDIUM | 5.4 | 0.2% | Feb 25, 2026 | TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS) ... |
| CVE-2026-27614 | MEDIUM | 6.1 | 0.3% | Feb 25, 2026 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit ev... |
| CVE-2026-27612 | MEDIUM | 6.1 | 0.2% | Feb 25, 2026 | Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` compon... |
| CVE-2026-27611 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when ... |
| CVE-2026-27610 | MEDIUM | 5.3 | 0.3% | Feb 25, 2026 | Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha... |
| CVE-2026-27609 | MEDIUM | 6.5 | 0.1% | Feb 25, 2026 | Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha... |
| CVE-2026-25135 | MEDIUM | 4.5 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2026-25127 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now