2026 CVE Vulnerabilities
53,398 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1447 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2026-1210 | MEDIUM | 6.4 | 0.3% | Feb 3, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_dat... |
| CVE-2026-0950 | MEDIUM | 5.3 | 0.3% | Feb 3, 2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Di... |
| CVE-2026-1788 | MEDIUM | 6.6 | 0.4% | Feb 3, 2026 | : Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet p... |
| CVE-2026-0909 | MEDIUM | 5.3 | 0.3% | Feb 3, 2026 | The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including... |
| CVE-2026-24935 | MEDIUM | 5.6 | 0.1% | Feb 3, 2026 | A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While... |
| CVE-2026-24933 | MEDIUM | 5.9 | 0.2% | Feb 3, 2026 | The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An ... |
| CVE-2026-24932 | MEDIUM | 5.9 | 0.2% | Feb 3, 2026 | The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Althou... |
| CVE-2026-25228 | MEDIUM | 4.3 | 0.4% | Feb 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerab... |
| CVE-2026-25144 | MEDIUM | 5.3 | 0.3% | Feb 2, 2026 | Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter i... |
| CVE-2026-24133 | MEDIUM | 6.5 | 0.6% | Feb 2, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage me... |
| CVE-2026-24043 | MEDIUM | 5.4 | 0.3% | Feb 2, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata... |
| CVE-2026-24040 | MEDIUM | 4.8 | 0.3% | Feb 2, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes ... |
| CVE-2026-24007 | MEDIUM | 4.6 | 0.1% | Feb 2, 2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protecti... |
| CVE-2026-23476 | MEDIUM | 5.4 | 0.3% | Feb 2, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected X... |
| CVE-2026-22780 | MEDIUM | 6.1 | 0.2% | Feb 2, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be expl... |
| CVE-2026-1770 | MEDIUM | 4.5 | 0.4% | Feb 2, 2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat... |
| CVE-2026-1232 | MEDIUM | 6.8 | 0.1% | Feb 2, 2026 | A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Und... |
| CVE-2026-1760 | MEDIUM | 5.3 | 0.4% | Feb 2, 2026 | A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles r... |
| CVE-2026-1757 | MEDIUM | 6.2 | 0.2% | Feb 2, 2026 | A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocat... |
| CVE-2026-20422 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2026-20421 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2026-20420 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2026-20419 | MEDIUM | 6.5 | 0.7% | Feb 2, 2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead ... |
| CVE-2026-20417 | MEDIUM | 5.3 | 0.1% | Feb 2, 2026 | In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now