2026 CVE Vulnerabilities
53,163 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27503 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search q... |
| CVE-2026-27502 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query p... |
| CVE-2026-26745 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration ... |
| CVE-2026-26100 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network... |
| CVE-2026-26099 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ... |
| CVE-2026-26098 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ... |
| CVE-2026-26097 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ... |
| CVE-2026-26096 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network... |
| CVE-2026-26095 | MEDIUM | 5.5 | 0.1% | Feb 20, 2026 | Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network... |
| CVE-2026-26049 | MEDIUM | 5.7 | 0.3% | Feb 20, 2026 | The web management interface of the device renders the passwords in a plaintext input field. The current password is di... |
| CVE-2026-1842 | MEDIUM | 6.2 | 0.2% | Feb 20, 2026 | HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and fa... |
| CVE-2026-24953 | MEDIUM | 6.5 | 0.4% | Feb 20, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple F... |
| CVE-2026-24946 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-deliver... |
| CVE-2026-24944 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-22350 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elem... |
| CVE-2026-22341 | MEDIUM | 6.7 | 0.4% | Feb 20, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authenticatio... |
| CVE-2026-2486 | MEDIUM | 6.4 | 0.2% | Feb 20, 2026 | The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_tabl... |
| CVE-2026-26370 | MEDIUM | 6.1 | 0.2% | Feb 20, 2026 | WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnera... |
| CVE-2026-2739 | MEDIUM | 5.5 | 0.5% | Feb 20, 2026 | This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state... |
| CVE-2026-2384 | MEDIUM | 6.4 | 0.2% | Feb 20, 2026 | The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortco... |
| CVE-2026-27017 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th... |
| CVE-2026-26994 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th... |
| CVE-2026-26993 | MEDIUM | 5.4 | 0.3% | Feb 20, 2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and ... |
| CVE-2026-26992 | MEDIUM | 4.8 | 0.2% | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port gro... |
| CVE-2026-26991 | MEDIUM | 4.8 | 0.2% | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device g... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now