2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0228 | LOW | 1.3 | 0.2% | Feb 11, 2026 | An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to ... |
| CVE-2026-2345 | LOW | 3.6 | 0.1% | Feb 11, 2026 | Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add... |
| CVE-2026-26013 | LOW | 3.7 | 0.4% | Feb 10, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_token... |
| CVE-2026-1762 | LOW | 2.9 | 0.2% | Feb 10, 2026 | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a... |
| CVE-2026-21249 | LOW | 3.3 | 11.4% | Feb 10, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-23901 | LOW | 2.5 | 0.2% | Feb 10, 2026 | Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.... |
| CVE-2026-24320 | LOW | 3.1 | 0.2% | Feb 10, 2026 | Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke... |
| CVE-2026-23686 | LOW | 3.4 | 0.2% | Feb 10, 2026 | Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr... |
| CVE-2026-2246 | LOW | 3.3 | 0.2% | Feb 9, 2026 | A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the ... |
| CVE-2026-2245 | LOW | 3.3 | 0.1% | Feb 9, 2026 | A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library sr... |
| CVE-2026-2215 | LOW | 3.7 | 0.3% | Feb 9, 2026 | A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the ... |
| CVE-2026-2069 | LOW | 3.3 | 0.1% | Feb 6, 2026 | A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the f... |
| CVE-2026-25764 | LOW | 3.5 | 0.2% | Feb 6, 2026 | OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injec... |
| CVE-2026-22254 | LOW | 3.5 | 0.3% | Feb 6, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS... |
| CVE-2026-1990 | LOW | 3.3 | 0.2% | Feb 6, 2026 | A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap... |
| CVE-2026-25815 | LOW | 3.2 | 0.1% | Feb 5, 2026 | Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp... |
| CVE-2026-1966 | LOW | 2.4 | 0.2% | Feb 5, 2026 | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated ... |
| CVE-2026-25517 | LOW | 2.7 | 0.3% | Feb 4, 2026 | Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7... |
| CVE-2026-20730 | LOW | 3.3 | 0.1% | Feb 4, 2026 | A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access ... |
| CVE-2026-1791 | LOW | 2.7 | 0.3% | Feb 4, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G... |
| CVE-2026-24513 | LOW | 3.1 | 0.3% | Feb 3, 2026 | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may ... |
| CVE-2026-25224 | LOW | 3.7 | 0.5% | Feb 3, 2026 | Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability... |
| CVE-2026-24934 | LOW | 3.7 | 0.2% | Feb 3, 2026 | The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an externa... |
| CVE-2026-1703 | LOW | 2 | 0.4% | Feb 2, 2026 | When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installati... |
| CVE-2026-1751 | LOW | 3.1 | 0.2% | Feb 2, 2026 | A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now