2026 CVE Vulnerabilities
55,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3378 | HIGH | 8.8 | 0.7% | Mar 1, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex... |
| CVE-2026-3377 | HIGH | 8.8 | 0.7% | Mar 1, 2026 | A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file... |
| CVE-2026-3376 | HIGH | 8.8 | 0.7% | Feb 28, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSaf... |
| CVE-2026-28557 | HIGH | 7.1 | 0.3% | Feb 28, 2026 | wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp... |
| CVE-2026-2844 | HIGH | 7.5 | 0.3% | Feb 28, 2026 | Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani... |
| CVE-2026-2471 | HIGH | 7.5 | 0.4% | Feb 28, 2026 | The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1... |
| CVE-2026-28516 | HIGH | 8.8 | 1.0% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The ... |
| CVE-2026-28515 | HIGH | 8.8 | 1.2% | Feb 27, 2026 | openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and conta... |
| CVE-2026-28425 | HIGH | 8 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenti... |
| CVE-2026-28423 | HIGH | 8.6 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide ... |
| CVE-2026-28421 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati... |
| CVE-2026-28417 | HIGH | 7.8 | 1.2% | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists... |
| CVE-2026-28416 | HIGH | 8.6 | 0.3% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo... |
| CVE-2026-28414 | HIGH | 7.5 | 3.1% | Feb 27, 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win... |
| CVE-2026-28409 | HIGH | 7.2 | 3.3% | Feb 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne... |
| CVE-2026-28406 | HIGH | 8.2 | 0.6% | Feb 27, 2026 | kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers... |
| CVE-2026-28402 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-28400 | HIGH | 7.5 | 0.2% | Feb 27, 2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e... |
| CVE-2026-27939 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6... |
| CVE-2026-28270 | HIGH | 7.2 | 1.6% | Feb 27, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl... |
| CVE-2026-27947 | HIGH | 8.8 | 0.7% | Feb 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an... |
| CVE-2026-27836 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p... |
| CVE-2026-27832 | HIGH | 8.8 | 0.2% | Feb 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, an... |
| CVE-2026-27757 | HIGH | 7.2 | 0.3% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic... |
| CVE-2026-27752 | HIGH | 8.2 | 0.2% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now