2026 CVE Vulnerabilities
53,349 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21317 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur... |
| CVE-2026-21316 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | Audition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that c... |
| CVE-2026-21315 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposur... |
| CVE-2026-21314 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur... |
| CVE-2026-21313 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur... |
| CVE-2026-21261 | MEDIUM | 5.5 | 0.6% | Feb 10, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-21258 | MEDIUM | 5.5 | 0.6% | Feb 10, 2026 | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-21222 | MEDIUM | 5.5 | 0.6% | Feb 10, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-1997 | MEDIUM | 5.3 | 0.2% | Feb 10, 2026 | Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, poten... |
| CVE-2026-1996 | MEDIUM | 5.3 | 0.3% | Feb 10, 2026 | Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled,... |
| CVE-2026-0653 | MEDIUM | 6.5 | 0.4% | Feb 10, 2026 | On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending... |
| CVE-2026-25530 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks... |
| CVE-2026-1602 | MEDIUM | 6.5 | 0.7% | Feb 10, 2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2026-1922 | MEDIUM | 6.4 | 0.2% | Feb 10, 2026 | The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2026-1722 | MEDIUM | 5.3 | 0.3% | Feb 10, 2026 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Obj... |
| CVE-2026-2099 | MEDIUM | 5.4 | 0.2% | Feb 10, 2026 | AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers... |
| CVE-2026-2098 | MEDIUM | 6.1 | 0.2% | Feb 10, 2026 | AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote atta... |
| CVE-2026-0996 | MEDIUM | 6.4 | 0.3% | Feb 10, 2026 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all... |
| CVE-2026-2259 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser... |
| CVE-2026-24328 | MEDIUM | 6.1 | 0.2% | Feb 10, 2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when cli... |
| CVE-2026-24327 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages),... |
| CVE-2026-24326 | MEDIUM | 4.3 | 0.2% | Feb 10, 2026 | Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker w... |
| CVE-2026-24325 | MEDIUM | 4.8 | 0.2% | Feb 10, 2026 | SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripti... |
| CVE-2026-24324 | MEDIUM | 6.5 | 0.3% | Feb 10, 2026 | SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to... |
| CVE-2026-24323 | MEDIUM | 6.1 | 0.2% | Feb 10, 2026 | The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now