2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23620 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListSe... |
| CVE-2026-23619 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains se... |
| CVE-2026-23618 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che... |
| CVE-2026-23617 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che... |
| CVE-2026-23616 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing co... |
| CVE-2026-23615 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Fr... |
| CVE-2026-23614 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Fr... |
| CVE-2026-23613 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklis... |
| CVE-2026-23612 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist... |
| CVE-2026-23611 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist man... |
| CVE-2026-23610 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange con... |
| CVE-2026-23609 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP S... |
| CVE-2026-23608 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring ... |
| CVE-2026-23607 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitel... |
| CVE-2026-23606 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content... |
| CVE-2026-23605 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filte... |
| CVE-2026-23604 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filterin... |
| CVE-2026-26223 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | SPIP before 4.4.8 allows cross-site scripting (XSS) in the private area via malicious iframe tags. The application does ... |
| CVE-2026-25766 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default fil... |
| CVE-2026-25739 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Version... |
| CVE-2026-25738 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Version... |
| CVE-2026-25527 | MEDIUM | 5.3 | 0.9% | Feb 19, 2026 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<grou... |
| CVE-2026-2718 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attri... |
| CVE-2026-2716 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Hea... |
| CVE-2026-22268 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now