2026 CVE Vulnerabilities
53,154 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27125 | MEDIUM | 6.8 | 0.4% | Feb 20, 2026 | svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e... |
| CVE-2026-27122 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side render... |
| CVE-2026-27121 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XS... |
| CVE-2026-27119 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering ou... |
| CVE-2026-27120 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape ht... |
| CVE-2026-27118 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/... |
| CVE-2026-27113 | MEDIUM | 6.3 | 0.4% | Feb 20, 2026 | Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and pr... |
| CVE-2026-27111 | MEDIUM | 5 | 0.2% | Feb 20, 2026 | Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model incl... |
| CVE-2026-27026 | MEDIUM | 5.5 | 0.2% | Feb 20, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra... |
| CVE-2026-27025 | MEDIUM | 5.5 | 0.2% | Feb 20, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra... |
| CVE-2026-27024 | MEDIUM | 5.5 | 0.2% | Feb 20, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra... |
| CVE-2026-27022 | MEDIUM | 6.5 | 3.7% | Feb 20, 2026 | @langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection ... |
| CVE-2026-27020 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inj... |
| CVE-2026-2852 | MEDIUM | 6.3 | 0.2% | Feb 20, 2026 | A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects th... |
| CVE-2026-2851 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability af... |
| CVE-2026-2850 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function ... |
| CVE-2026-2832 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing add... |
| CVE-2026-2849 | MEDIUM | 6.3 | 0.2% | Feb 20, 2026 | A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issu... |
| CVE-2026-27506 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow ... |
| CVE-2026-27505 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (i... |
| CVE-2026-27504 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the ... |
| CVE-2026-27503 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search q... |
| CVE-2026-27502 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query p... |
| CVE-2026-26745 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration ... |
| CVE-2026-26100 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now