2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25591 | MEDIUM | 6.5 | 0.5% | Feb 24, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2026-25576 | MEDIUM | 5.5 | 0.2% | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-24484 | MEDIUM | 5.3 | 0.4% | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-3043 | MEDIUM | 6.1 | 0.3% | Feb 24, 2026 | A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the fi... |
| CVE-2026-3063 | MEDIUM | 5.4 | 0.2% | Feb 23, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a us... |
| CVE-2026-3028 | MEDIUM | 6.1 | 0.3% | Feb 23, 2026 | A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file... |
| CVE-2026-27742 | MEDIUM | 5.4 | 0.1% | Feb 23, 2026 | Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The ... |
| CVE-2026-27741 | MEDIUM | 4.3 | 0.1% | Feb 23, 2026 | Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /ad... |
| CVE-2026-3075 | MEDIUM | 5.3 | 0.3% | Feb 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat ... |
| CVE-2026-3027 | MEDIUM | 6.1 | 0.3% | Feb 23, 2026 | A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-... |
| CVE-2026-23694 | MEDIUM | 5.1 | 0.2% | Feb 23, 2026 | Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery ... |
| CVE-2026-23521 | MEDIUM | 6.5 | 0.3% | Feb 23, 2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat... |
| CVE-2026-26464 | MEDIUM | 6.1 | 0.2% | Feb 23, 2026 | Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, w... |
| CVE-2026-2698 | MEDIUM | 6.5 | 0.2% | Feb 23, 2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authoriz... |
| CVE-2026-27513 | MEDIUM | 5.1 | 0.1% | Feb 23, 2026 | Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability... |
| CVE-2026-27512 | MEDIUM | 6.1 | 0.2% | Feb 23, 2026 | Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the adm... |
| CVE-2026-27511 | MEDIUM | 5.1 | 0.2% | Feb 23, 2026 | Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based adm... |
| CVE-2026-2985 | MEDIUM | 6.3 | 0.3% | Feb 23, 2026 | A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloa... |
| CVE-2026-2984 | MEDIUM | 6.5 | 0.5% | Feb 23, 2026 | A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function ... |
| CVE-2026-26365 | MEDIUM | 4 | 0.2% | Feb 23, 2026 | Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where... |
| CVE-2026-2976 | MEDIUM | 6.5 | 0.3% | Feb 23, 2026 | A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller o... |
| CVE-2026-2975 | MEDIUM | 5.5 | 0.4% | Feb 23, 2026 | A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_ap... |
| CVE-2026-2972 | MEDIUM | 5.4 | 0.3% | Feb 23, 2026 | A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso... |
| CVE-2026-2971 | MEDIUM | 6.1 | 0.3% | Feb 23, 2026 | A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of t... |
| CVE-2026-2997 | MEDIUM | 6.5 | 0.2% | Feb 23, 2026 | Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now