2026 CVE Vulnerabilities
53,345 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25828 | MEDIUM | 5.4 | 1.2% | Feb 12, 2026 | grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because... |
| CVE-2026-26005 | MEDIUM | 5 | 0.2% | Feb 12, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows ... |
| CVE-2026-26000 | MEDIUM | 6.1 | 0.3% | Feb 12, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0... |
| CVE-2026-0619 | MEDIUM | 6 | 0.3% | Feb 12, 2026 | A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to t... |
| CVE-2026-25933 | MEDIUM | 6.8 | 0.2% | Feb 12, 2026 | Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in t... |
| CVE-2026-25768 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadat... |
| CVE-2026-22821 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vul... |
| CVE-2026-21438 | MEDIUM | 5.3 | 0.4% | Feb 12, 2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo... |
| CVE-2026-2003 | MEDIUM | 4.3 | 0.3% | Feb 12, 2026 | Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. ... |
| CVE-2026-1671 | MEDIUM | 6.5 | 0.3% | Feb 12, 2026 | The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2026-2276 | MEDIUM | 5.3 | 0.4% | Feb 12, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in the Wix web application, where the endpoint ' https://manage.wix.c... |
| CVE-2026-1356 | MEDIUM | 4.8 | 0.2% | Feb 12, 2026 | The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Reques... |
| CVE-2026-21722 | MEDIUM | 5.3 | 0.3% | Feb 12, 2026 | Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi... |
| CVE-2026-1537 | MEDIUM | 5.3 | 0.2% | Feb 12, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2026-20682 | MEDIUM | 5.3 | 0.2% | Feb 11, 2026 | A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.... |
| CVE-2026-20680 | MEDIUM | 6.5 | 0.1% | Feb 11, 2026 | The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7... |
| CVE-2026-20678 | MEDIUM | 5.5 | 0.1% | Feb 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5... |
| CVE-2026-20676 | MEDIUM | 5.3 | 0.2% | Feb 11, 2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3... |
| CVE-2026-20675 | MEDIUM | 5.5 | 0.2% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and i... |
| CVE-2026-20674 | MEDIUM | 4.6 | 0.1% | Feb 11, 2026 | A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker w... |
| CVE-2026-20673 | MEDIUM | 5.3 | 0.3% | Feb 11, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.... |
| CVE-2026-20669 | MEDIUM | 5.5 | 0.1% | Feb 11, 2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2026-20666 | MEDIUM | 5.5 | 0.1% | Feb 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may... |
| CVE-2026-20662 | MEDIUM | 4.6 | 0.2% | Feb 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ... |
| CVE-2026-20661 | MEDIUM | 4.6 | 0.2% | Feb 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now