2026 CVE Vulnerabilities
53,226 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0829 | MEDIUM | 5.8 | 0.7% | Feb 17, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s... |
| CVE-2026-1657 | MEDIUM | 5.3 | 0.4% | Feb 17, 2026 | The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including... |
| CVE-2026-2002 | MEDIUM | 4.4 | 0.2% | Feb 17, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-2565 | MEDIUM | 6.6 | 0.8% | Feb 16, 2026 | A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the ... |
| CVE-2026-2032 | MEDIUM | 4.3 | 0.1% | Feb 16, 2026 | Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page con... |
| CVE-2026-2560 | MEDIUM | 6.3 | 1.7% | Feb 16, 2026 | A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file p... |
| CVE-2026-2558 | MEDIUM | 6.3 | 0.2% | Feb 16, 2026 | A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_h... |
| CVE-2026-2557 | MEDIUM | 5.4 | 0.2% | Feb 16, 2026 | A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller... |
| CVE-2026-2556 | MEDIUM | 6.3 | 0.3% | Feb 16, 2026 | A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file... |
| CVE-2026-1046 | MEDIUM | 6.5 | 0.2% | Feb 16, 2026 | Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost ser... |
| CVE-2026-2553 | MEDIUM | 6.3 | 0.2% | Feb 16, 2026 | A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d1... |
| CVE-2026-2552 | MEDIUM | 5.5 | 0.4% | Feb 16, 2026 | A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/... |
| CVE-2026-2551 | MEDIUM | 5.4 | 0.5% | Feb 16, 2026 | A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file... |
| CVE-2026-2452 | MEDIUM | 6.5 | 0.3% | Feb 16, 2026 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used... |
| CVE-2026-2451 | MEDIUM | 6.5 | 0.3% | Feb 16, 2026 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used... |
| CVE-2026-2415 | MEDIUM | 5.9 | 0.2% | Feb 16, 2026 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used... |
| CVE-2026-0999 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restri... |
| CVE-2026-0998 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 ... |
| CVE-2026-0997 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 ... |
| CVE-2026-2548 | MEDIUM | 6.3 | 1.4% | Feb 16, 2026 | A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manip... |
| CVE-2026-2547 | MEDIUM | 6.1 | 0.3% | Feb 16, 2026 | A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the fil... |
| CVE-2026-2546 | MEDIUM | 6.1 | 0.3% | Feb 16, 2026 | A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t... |
| CVE-2026-2545 | MEDIUM | 6.1 | 0.2% | Feb 16, 2026 | A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A... |
| CVE-2026-2543 | MEDIUM | 5.1 | 0.3% | Feb 16, 2026 | A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i... |
| CVE-2026-0929 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now