2026 CVE Vulnerabilities
53,393 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25483 | MEDIUM | 5.4 | 0.3% | Feb 3, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s... |
| CVE-2026-25482 | MEDIUM | 4.8 | 0.3% | Feb 3, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s... |
| CVE-2026-24427 | MEDIUM | 5.5 | 0.1% | Feb 3, 2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. ... |
| CVE-2026-24426 | MEDIUM | 6.1 | 0.2% | Feb 3, 2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the w... |
| CVE-2026-0620 | MEDIUM | 6 | 0.2% | Feb 3, 2026 | When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, ev... |
| CVE-2026-24774 | MEDIUM | 4.3 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24674 | MEDIUM | 6.1 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24673 | MEDIUM | 5.3 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24672 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24671 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24670 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24668 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24667 | MEDIUM | 5 | 0.1% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24666 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24665 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24664 | MEDIUM | 5.3 | 0.3% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-22228 | MEDIUM | 4.9 | 0.3% | Feb 3, 2026 | An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by res... |
| CVE-2026-22220 | MEDIUM | 4.5 | 0.2% | Feb 3, 2026 | A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a cra... |
| CVE-2026-23795 | MEDIUM | 4.9 | 0.8% | Feb 3, 2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with ade... |
| CVE-2026-23794 | MEDIUM | 6.8 | 0.4% | Feb 3, 2026 | Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a maliciou... |
| CVE-2026-25036 | MEDIUM | 6.5 | 0.3% | Feb 3, 2026 | Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-25028 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-ele... |
| CVE-2026-25024 | MEDIUM | 5.4 | 0.1% | Feb 3, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site ... |
| CVE-2026-25023 | MEDIUM | 5.3 | 0.2% | Feb 3, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles... |
| CVE-2026-25021 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now