2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0549 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortc... |
| CVE-2026-2683 | MEDIUM | 4.3 | 0.5% | Feb 18, 2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an ... |
| CVE-2026-2676 | MEDIUM | 6.3 | 0.3% | Feb 18, 2026 | A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issu... |
| CVE-2026-26281 | MEDIUM | 4.4 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site ... |
| CVE-2026-26270 | MEDIUM | 5.4 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-25596 | MEDIUM | 4.8 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-25595 | MEDIUM | 4.8 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-25594 | MEDIUM | 4.8 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-2672 | MEDIUM | 5.3 | 0.6% | Feb 18, 2026 | A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this ... |
| CVE-2026-2669 | MEDIUM | 6.5 | 0.5% | Feb 18, 2026 | A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impac... |
| CVE-2026-27178 | MEDIUM | 6.1 | 0.2% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method paramete... |
| CVE-2026-27177 | MEDIUM | 6.1 | 0.2% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=se... |
| CVE-2026-27176 | MEDIUM | 6.1 | 0.4% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The ... |
| CVE-2026-2667 | MEDIUM | 5.5 | 0.6% | Feb 18, 2026 | A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impact... |
| CVE-2026-1999 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th... |
| CVE-2026-1355 | MEDIUM | 6.5 | 0.4% | Feb 18, 2026 | A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unau... |
| CVE-2026-1200 | MEDIUM | 6.3 | 0.3% | Feb 18, 2026 | A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `... |
| CVE-2026-0665 | MEDIUM | 6.5 | 0.1% | Feb 18, 2026 | An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-b... |
| CVE-2026-2665 | MEDIUM | 6.3 | 0.3% | Feb 18, 2026 | A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the fu... |
| CVE-2026-2663 | MEDIUM | 6.3 | 0.2% | Feb 18, 2026 | A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown proc... |
| CVE-2026-25500 | MEDIUM | 5.4 | 0.2% | Feb 18, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an... |
| CVE-2026-2658 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unkno... |
| CVE-2026-20144 | MEDIUM | 4.9 | 0.4% | Feb 18, 2026 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 1... |
| CVE-2026-20142 | MEDIUM | 4.9 | 0.3% | Feb 18, 2026 | In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SH... |
| CVE-2026-20141 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now