2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25124 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24896 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24849 | MEDIUM | 6.5 | 2.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24847 | MEDIUM | 6.1 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-21443 | MEDIUM | 6.1 | 0.1% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-27598 | MEDIUM | 6.5 | 0.6% | Feb 25, 2026 | Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG`... |
| CVE-2026-26351 | MEDIUM | 4.8 | 0.3% | Feb 24, 2026 | GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS... |
| CVE-2026-27204 | MEDIUM | 6.5 | 0.3% | Feb 24, 2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen... |
| CVE-2026-3131 | MEDIUM | 6.5 | 0.3% | Feb 24, 2026 | Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an au... |
| CVE-2026-27477 | MEDIUM | 5.9 | 0.3% | Feb 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b... |
| CVE-2026-23858 | MEDIUM | 5.4 | 0.2% | Feb 24, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Gener... |
| CVE-2026-1768 | MEDIUM | 4.3 | 0.2% | Feb 24, 2026 | A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to acc... |
| CVE-2026-27156 | MEDIUM | 6.1 | 0.2% | Feb 24, 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side... |
| CVE-2026-25603 | MEDIUM | 6.6 | 0.3% | Feb 24, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys ... |
| CVE-2026-27589 | MEDIUM | 6.5 | 0.2% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (def... |
| CVE-2026-27585 | MEDIUM | 6.5 | 0.3% | Feb 24, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine ... |
| CVE-2026-27518 | MEDIUM | 5.1 | 0.1% | Feb 24, 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing... |
| CVE-2026-27517 | MEDIUM | 6.1 | 0.1% | Feb 24, 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the we... |
| CVE-2026-27568 | MEDIUM | 6.1 | 0.2% | Feb 24, 2026 | WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses P... |
| CVE-2026-27567 | MEDIUM | 4.8 | 0.3% | Feb 24, 2026 | Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SS... |
| CVE-2026-0402 | MEDIUM | 4.9 | 0.3% | Feb 24, 2026 | A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0401 | MEDIUM | 4.9 | 0.3% | Feb 24, 2026 | A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0400 | MEDIUM | 4.9 | 0.4% | Feb 24, 2026 | A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. |
| CVE-2026-0399 | MEDIUM | 4.9 | 0.3% | Feb 24, 2026 | Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to impr... |
| CVE-2026-2804 | MEDIUM | 5.4 | 0.3% | Feb 24, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now