2026 CVE Vulnerabilities
53,351 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25905 | MEDIUM | 5.8 | 0.2% | Feb 9, 2026 | The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any ... |
| CVE-2026-25904 | MEDIUM | 5.8 | 0.2% | Feb 9, 2026 | The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the ... |
| CVE-2026-2222 | MEDIUM | 4.8 | 0.2% | Feb 9, 2026 | A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown... |
| CVE-2026-2216 | MEDIUM | 4.3 | 0.3% | Feb 9, 2026 | A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file... |
| CVE-2026-22613 | MEDIUM | 5.7 | 0.2% | Feb 9, 2026 | The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential... |
| CVE-2026-2214 | MEDIUM | 4.8 | 0.2% | Feb 9, 2026 | A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/... |
| CVE-2026-2201 | MEDIUM | 5.4 | 0.2% | Feb 9, 2026 | A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. Thi... |
| CVE-2026-2200 | MEDIUM | 4.8 | 0.2% | Feb 9, 2026 | A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/sav... |
| CVE-2026-2160 | MEDIUM | 6.1 | 0.3% | Feb 8, 2026 | A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability i... |
| CVE-2026-2159 | MEDIUM | 6.1 | 0.4% | Feb 8, 2026 | A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the fi... |
| CVE-2026-2156 | MEDIUM | 4.8 | 0.2% | Feb 8, 2026 | A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown... |
| CVE-2026-2154 | MEDIUM | 6.1 | 0.3% | Feb 8, 2026 | A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impact... |
| CVE-2026-2153 | MEDIUM | 6.1 | 0.3% | Feb 8, 2026 | A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the f... |
| CVE-2026-2150 | MEDIUM | 6.1 | 0.4% | Feb 8, 2026 | A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi... |
| CVE-2026-2149 | MEDIUM | 6.1 | 0.4% | Feb 8, 2026 | A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected... |
| CVE-2026-2147 | MEDIUM | 5.5 | 0.5% | Feb 8, 2026 | A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download... |
| CVE-2026-2145 | MEDIUM | 5.4 | 0.3% | Feb 8, 2026 | A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the fil... |
| CVE-2026-2209 | MEDIUM | 4.3 | 0.2% | Feb 8, 2026 | A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file ... |
| CVE-2026-2208 | MEDIUM | 6.5 | 0.2% | Feb 8, 2026 | A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi... |
| CVE-2026-2207 | MEDIUM | 6.9 | 0.3% | Feb 8, 2026 | A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public... |
| CVE-2026-2205 | MEDIUM | 5.3 | 0.2% | Feb 8, 2026 | A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j... |
| CVE-2026-25568 | MEDIUM | 4.3 | 0.2% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow... |
| CVE-2026-25567 | MEDIUM | 4.3 | 0.2% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en... |
| CVE-2026-25566 | MEDIUM | 5.4 | 0.2% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination... |
| CVE-2026-25565 | MEDIUM | 6.5 | 0.3% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now