2026 CVE Vulnerabilities
53,154 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27485 | MEDIUM | 4.4 | 0.2% | Feb 21, 2026 | OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a l... |
| CVE-2026-27484 | MEDIUM | 4.3 | 0.2% | Feb 21, 2026 | OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, k... |
| CVE-2026-27482 | MEDIUM | 6.5 | 0.3% | Feb 21, 2026 | Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but d... |
| CVE-2026-27480 | MEDIUM | 5.3 | 0.3% | Feb 21, 2026 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 thro... |
| CVE-2026-2864 | MEDIUM | 5.4 | 0.3% | Feb 21, 2026 | A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07... |
| CVE-2026-27469 | MEDIUM | 6.1 | 0.2% | Feb 21, 2026 | Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee0... |
| CVE-2026-27464 | MEDIUM | 6.5 | 0.3% | Feb 21, 2026 | Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, aut... |
| CVE-2026-27458 | MEDIUM | 5.4 | 0.2% | Feb 21, 2026 | LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting v... |
| CVE-2026-27452 | MEDIUM | 5.3 | 0.3% | Feb 21, 2026 | ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In... |
| CVE-2026-2863 | MEDIUM | 5.4 | 0.4% | Feb 21, 2026 | A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. T... |
| CVE-2026-2861 | MEDIUM | 5.5 | 0.5% | Feb 21, 2026 | A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Chang... |
| CVE-2026-27210 | MEDIUM | 6.1 | 0.3% | Feb 21, 2026 | Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot ... |
| CVE-2026-27205 | MEDIUM | 4.3 | 0.4% | Feb 21, 2026 | Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session ... |
| CVE-2026-27199 | MEDIUM | 5.3 | 0.6% | Feb 21, 2026 | Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Window... |
| CVE-2026-26047 | MEDIUM | 6.5 | 0.4% | Feb 21, 2026 | A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimete... |
| CVE-2026-2860 | MEDIUM | 6.3 | 0.3% | Feb 21, 2026 | A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d07... |
| CVE-2026-27196 | MEDIUM | 4.8 | 0.3% | Feb 21, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-a... |
| CVE-2026-27193 | MEDIUM | 5.3 | 0.4% | Feb 21, 2026 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.... |
| CVE-2026-27191 | MEDIUM | 6.1 | 0.3% | Feb 21, 2026 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.3... |
| CVE-2026-27189 | MEDIUM | 5.8 | 0.1% | Feb 21, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a... |
| CVE-2026-27147 | MEDIUM | 5.4 | 0.2% | Feb 21, 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploa... |
| CVE-2026-27146 | MEDIUM | 4.5 | 0.2% | Feb 21, 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi... |
| CVE-2026-2490 | MEDIUM | 5.5 | 0.3% | Feb 20, 2026 | RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows... |
| CVE-2026-2035 | MEDIUM | 6.8 | 1.5% | Feb 20, 2026 | Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2026-27133 | MEDIUM | 5.9 | 0.2% | Feb 20, 2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now