2026 CVE Vulnerabilities
53,356 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25566 | MEDIUM | 5.4 | 0.2% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination... |
| CVE-2026-25565 | MEDIUM | 6.5 | 0.3% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo... |
| CVE-2026-25562 | MEDIUM | 4.3 | 0.3% | Feb 7, 2026 | WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment ... |
| CVE-2026-2111 | MEDIUM | 4.3 | 0.5% | Feb 7, 2026 | A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the fil... |
| CVE-2026-1675 | MEDIUM | 5.3 | 0.3% | Feb 7, 2026 | The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu... |
| CVE-2026-1643 | MEDIUM | 6.1 | 0.3% | Feb 7, 2026 | The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including... |
| CVE-2026-1634 | MEDIUM | 6.1 | 0.3% | Feb 7, 2026 | The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2026-1613 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcod... |
| CVE-2026-1611 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops... |
| CVE-2026-1608 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode... |
| CVE-2026-1573 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The OMIGO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `omigo_donate_button` short... |
| CVE-2026-1570 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2026-1082 | MEDIUM | 4.3 | 0.2% | Feb 7, 2026 | The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-0555 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX ... |
| CVE-2026-2074 | MEDIUM | 6.3 | 0.3% | Feb 7, 2026 | A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs... |
| CVE-2026-25757 | MEDIUM | 5.3 | 0.4% | Feb 6, 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,... |
| CVE-2026-25749 | MEDIUM | 6.6 | 0.2% | Feb 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists ... |
| CVE-2026-25760 | MEDIUM | 6.5 | 0.5% | Feb 6, 2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th... |
| CVE-2026-25574 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direc... |
| CVE-2026-25516 | MEDIUM | 6.1 | 0.2% | Feb 6, 2026 | NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown conte... |
| CVE-2026-25123 | MEDIUM | 5.3 | 0.3% | Feb 6, 2026 | Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an... |
| CVE-2026-25729 | MEDIUM | 6.5 | 0.2% | Feb 6, 2026 | DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co... |
| CVE-2026-25631 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'... |
| CVE-2026-25597 | MEDIUM | 5.3 | 0.3% | Feb 6, 2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio... |
| CVE-2026-25581 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control config... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now