2026 CVE Vulnerabilities
53,386 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23060 | MEDIUM | 5.5 | 0.1% | Feb 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen... |
| CVE-2026-20123 | MEDIUM | 6.1 | 0.2% | Feb 4, 2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2026-20111 | MEDIUM | 4.8 | 0.2% | Feb 4, 2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote... |
| CVE-2026-20056 | MEDIUM | 4 | 0.1% | Feb 4, 2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S... |
| CVE-2026-22549 | MEDIUM | 6.9 | 0.3% | Feb 4, 2026 | A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr... |
| CVE-2026-20732 | MEDIUM | 4.3 | 0.2% | Feb 4, 2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes... |
| CVE-2026-0873 | MEDIUM | 4.8 | 0.2% | Feb 4, 2026 | On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptob... |
| CVE-2026-1622 | MEDIUM | 4.8 | 0.1% | Feb 4, 2026 | Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential informatio... |
| CVE-2026-1370 | MEDIUM | 4.9 | 0.3% | Feb 4, 2026 | The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedI... |
| CVE-2026-0816 | MEDIUM | 4.9 | 0.3% | Feb 4, 2026 | The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para... |
| CVE-2026-0743 | MEDIUM | 4.4 | 0.3% | Feb 4, 2026 | The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' para... |
| CVE-2026-0742 | MEDIUM | 6.4 | 0.3% | Feb 4, 2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form... |
| CVE-2026-0681 | MEDIUM | 4.4 | 0.3% | Feb 4, 2026 | The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se... |
| CVE-2026-0679 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in ... |
| CVE-2026-0572 | MEDIUM | 6.5 | 0.3% | Feb 4, 2026 | The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2026-24447 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such m... |
| CVE-2026-23704 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitr... |
| CVE-2026-22875 | MEDIUM | 5.4 | 0.2% | Feb 4, 2026 | Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an atta... |
| CVE-2026-21393 | MEDIUM | 5.4 | 0.2% | Feb 4, 2026 | Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an atta... |
| CVE-2026-20986 | MEDIUM | 5.5 | 0.2% | Feb 4, 2026 | Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Sam... |
| CVE-2026-20985 | MEDIUM | 4.3 | 0.3% | Feb 4, 2026 | Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL... |
| CVE-2026-20984 | MEDIUM | 5.1 | 0.1% | Feb 4, 2026 | Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 ... |
| CVE-2026-20982 | MEDIUM | 6 | 0.3% | Feb 4, 2026 | Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with s... |
| CVE-2026-20981 | MEDIUM | 6.6 | 0.2% | Feb 4, 2026 | Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execut... |
| CVE-2026-20980 | MEDIUM | 6.8 | 0.2% | Feb 4, 2026 | Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now