2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23749 | LOW | 2.9 | 0.2% | Feb 26, 2026 | Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to impr... |
| CVE-2026-3193 | LOW | 3.1 | 0.2% | Feb 25, 2026 | A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. Th... |
| CVE-2026-3189 | LOW | 3.1 | 0.2% | Feb 25, 2026 | A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code ... |
| CVE-2026-3206 | LOW | 1.3 | 0.3% | Feb 25, 2026 | Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU Kr... |
| CVE-2026-28196 | LOW | 2.3 | 0.1% | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
| CVE-2026-21725 | LOW | 2 | 0.2% | Feb 25, 2026 | A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w... |
| CVE-2026-27632 | LOW | 3.1 | 0.1% | Feb 25, 2026 | Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar a... |
| CVE-2026-23859 | LOW | 2.7 | 0.3% | Feb 24, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnera... |
| CVE-2026-3041 | LOW | 2.4 | 0.3% | Feb 23, 2026 | A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the f... |
| CVE-2026-22568 | LOW | 2.7 | 0.2% | Feb 23, 2026 | Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated ... |
| CVE-2026-22567 | LOW | 2.7 | 0.2% | Feb 23, 2026 | Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate ba... |
| CVE-2026-2974 | LOW | 2.5 | 0.1% | Feb 23, 2026 | A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of... |
| CVE-2026-2968 | LOW | 3.7 | 0.2% | Feb 23, 2026 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of t... |
| CVE-2026-2967 | LOW | 3.7 | 0.5% | Feb 23, 2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file... |
| CVE-2026-2966 | LOW | 3.7 | 0.4% | Feb 23, 2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the ... |
| CVE-2026-2965 | LOW | 2.4 | 0.2% | Feb 23, 2026 | A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown ... |
| CVE-2026-2903 | LOW | 3.3 | 0.1% | Feb 22, 2026 | A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src... |
| CVE-2026-2889 | LOW | 3.3 | 0.1% | Feb 21, 2026 | A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx... |
| CVE-2026-27467 | LOW | 2.4 | 0.2% | Feb 21, 2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the m... |
| CVE-2026-22885 | LOW | 3.7 | 0.4% | Feb 20, 2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th... |
| CVE-2026-21620 | LOW | 2.3 | 0.5% | Feb 20, 2026 | Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file mo... |
| CVE-2026-2825 | LOW | 3.5 | 0.2% | Feb 20, 2026 | A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file t... |
| CVE-2026-27007 | LOW | 3.3 | 0.2% | Feb 20, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.2.15, `normalizeForHash` in `src/agents/sandbox/config-hash.t... |
| CVE-2026-26964 | LOW | 2.7 | 0.3% | Feb 20, 2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.63... |
| CVE-2026-26958 | LOW | 1.7 | 0.4% | Feb 19, 2026 | filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now