2026 CVE Vulnerabilities
53,351 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25492 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save... |
| CVE-2026-25491 | MEDIUM | 4.8 | 0.3% | Feb 9, 2026 | Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type na... |
| CVE-2026-25480 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to fil... |
| CVE-2026-25479 | MEDIUM | 6.5 | 0.3% | Feb 9, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_h... |
| CVE-2026-25478 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex... |
| CVE-2026-25230 | MEDIUM | 5.4 | 0.2% | Feb 9, 2026 | FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an au... |
| CVE-2026-24900 | MEDIUM | 6.5 | 0.3% | Feb 9, 2026 | MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_... |
| CVE-2026-24777 | MEDIUM | 6.7 | 0.3% | Feb 9, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permi... |
| CVE-2026-2242 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/cor... |
| CVE-2026-2241 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/o... |
| CVE-2026-21419 | MEDIUM | 6.6 | 0.1% | Feb 9, 2026 | Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Acce... |
| CVE-2026-2240 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef... |
| CVE-2026-24095 | MEDIUM | 5.3 | 0.2% | Feb 9, 2026 | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows... |
| CVE-2026-24027 | MEDIUM | 5.3 | 0.4% | Feb 9, 2026 | Crafted zones can lead to increased incoming network traffic. |
| CVE-2026-0398 | MEDIUM | 5.3 | 0.4% | Feb 9, 2026 | Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor. |
| CVE-2026-1960 | MEDIUM | 5.1 | 0.4% | Feb 9, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/Con... |
| CVE-2026-1959 | MEDIUM | 5.1 | 0.4% | Feb 9, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/... |
| CVE-2026-0632 | MEDIUM | 5.4 | 0.2% | Feb 9, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to... |
| CVE-2026-25847 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible |
| CVE-2026-25846 | MEDIUM | 6.5 | 0.9% | Feb 9, 2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs |
| CVE-2026-24098 | MEDIUM | 6.5 | 0.7% | Feb 9, 2026 | Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or mo... |
| CVE-2026-22922 | MEDIUM | 6.5 | 0.4% | Feb 9, 2026 | Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with cust... |
| CVE-2026-23903 | MEDIUM | 5.3 | 0.4% | Feb 9, 2026 | Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. ... |
| CVE-2026-2224 | MEDIUM | 5.4 | 0.2% | Feb 9, 2026 | A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /syst... |
| CVE-2026-25916 | MEDIUM | 4.3 | 0.6% | Feb 9, 2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now