2026 CVE Vulnerabilities
53,362 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25198 | MEDIUM | 5.1 | 0.3% | Feb 5, 2026 | web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vu... |
| CVE-2026-1268 | MEDIUM | 6.4 | 0.3% | Feb 5, 2026 | The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content fiel... |
| CVE-2026-1246 | MEDIUM | 4.9 | 0.5% | Feb 5, 2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load... |
| CVE-2026-0867 | MEDIUM | 6.4 | 0.3% | Feb 5, 2026 | The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-a... |
| CVE-2026-1898 | MEDIUM | 6.3 | 0.3% | Feb 5, 2026 | A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/... |
| CVE-2026-1897 | MEDIUM | 5.3 | 0.3% | Feb 5, 2026 | A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m... |
| CVE-2026-1896 | MEDIUM | 6.3 | 0.3% | Feb 5, 2026 | A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMig... |
| CVE-2026-1895 | MEDIUM | 6.3 | 0.3% | Feb 4, 2026 | A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the com... |
| CVE-2026-1894 | MEDIUM | 5.4 | 0.2% | Feb 4, 2026 | A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js ... |
| CVE-2026-25579 | MEDIUM | 6.5 | 0.5% | Feb 4, 2026 | Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users... |
| CVE-2026-25578 | MEDIUM | 6.1 | 0.3% | Feb 4, 2026 | Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site script... |
| CVE-2026-25543 | MEDIUM | 6.1 | 0.2% | Feb 4, 2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. ... |
| CVE-2026-25540 | MEDIUM | 6.5 | 0.4% | Feb 4, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas... |
| CVE-2026-25523 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin ur... |
| CVE-2026-25518 | MEDIUM | 5.9 | 0.3% | Feb 4, 2026 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc... |
| CVE-2026-1892 | MEDIUM | 5 | 0.2% | Feb 4, 2026 | A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model... |
| CVE-2026-1884 | MEDIUM | 4.9 | 0.4% | Feb 4, 2026 | A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file ... |
| CVE-2026-25511 | MEDIUM | 4.9 | 0.4% | Feb 4, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a... |
| CVE-2026-1554 | MEDIUM | 4.2 | 0.2% | Feb 4, 2026 | XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv... |
| CVE-2026-1553 | MEDIUM | 4.8 | 0.1% | Feb 4, 2026 | Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas:... |
| CVE-2026-0948 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri... |
| CVE-2026-0947 | MEDIUM | 4.8 | 0.1% | Feb 4, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet... |
| CVE-2026-0946 | MEDIUM | 6.1 | 0.1% | Feb 4, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet... |
| CVE-2026-0944 | MEDIUM | 5.3 | 0.2% | Feb 4, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This ... |
| CVE-2026-25475 | MEDIUM | 6.5 | 0.7% | Feb 4, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now