2026 CVE Vulnerabilities
53,356 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2064 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona... |
| CVE-2026-25727 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any t... |
| CVE-2026-25642 | MEDIUM | 6.1 | 0.2% | Feb 6, 2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th... |
| CVE-2026-25640 | MEDIUM | 5.4 | 0.3% | Feb 6, 2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to befor... |
| CVE-2026-25651 | MEDIUM | 6.1 | 0.2% | Feb 6, 2026 | client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Vers... |
| CVE-2026-25647 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has... |
| CVE-2026-24418 | MEDIUM | 6.5 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e... |
| CVE-2026-24417 | MEDIUM | 6.5 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e... |
| CVE-2026-24416 | MEDIUM | 6.5 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e... |
| CVE-2026-24050 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profil... |
| CVE-2026-25723 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p... |
| CVE-2026-24903 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was d... |
| CVE-2026-24776 | MEDIUM | 4.3 | 0.2% | Feb 6, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a... |
| CVE-2026-24419 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e... |
| CVE-2026-23633 | MEDIUM | 6.5 | 0.5% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p... |
| CVE-2026-23632 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte... |
| CVE-2026-22592 | MEDIUM | 6.5 | 0.3% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac... |
| CVE-2026-1769 | MEDIUM | 5.4 | 0.1% | Feb 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr... |
| CVE-2026-23739 | MEDIUM | 6.5 | 0.2% | Feb 6, 2026 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1... |
| CVE-2026-23738 | MEDIUM | 6.1 | 0.2% | Feb 6, 2026 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1... |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can... |
| CVE-2026-1293 | MEDIUM | 6.4 | 0.2% | Feb 6, 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-24928 | MEDIUM | 5.5 | 0.1% | Feb 6, 2026 | Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2026-24927 | MEDIUM | 5.5 | 0.1% | Feb 6, 2026 | Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2026-24924 | MEDIUM | 5.5 | 0.1% | Feb 6, 2026 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now