2026 CVE Vulnerabilities
55,810 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27752 | HIGH | 8.2 | 0.2% | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, al... |
| CVE-2026-26862 | HIGH | 8.3 | 0.4% | Feb 27, 2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag... |
| CVE-2026-26861 | HIGH | 8.3 | 0.2% | Feb 27, 2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han... |
| CVE-2026-21619 | HIGH | 7.5 | 0.6% | Feb 27, 2026 | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), ... |
| CVE-2026-25147 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-3304 | HIGH | 7.5 | 0.7% | Feb 27, 2026 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo... |
| CVE-2026-2749 | HIGH | 8.8 | 0.5% | Feb 27, 2026 | Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue aff... |
| CVE-2026-2359 | HIGH | 7.5 | 0.7% | Feb 27, 2026 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo... |
| CVE-2026-3223 | HIGH | 7.8 | 0.1% | Feb 27, 2026 | Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. |
| CVE-2026-2252 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft... |
| CVE-2026-1627 | HIGH | 8.1 | 0.2% | Feb 27, 2026 | An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromis... |
| CVE-2026-27776 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only... |
| CVE-2026-0980 | HIGH | 8.8 | 0.8% | Feb 27, 2026 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An... |
| CVE-2026-28372 | HIGH | 7.8 | 0.4% | Feb 27, 2026 | telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden... |
| CVE-2026-3292 | HIGH | 8.8 | 0.4% | Feb 27, 2026 | A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph... |
| CVE-2026-1442 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a... |
| CVE-2026-2428 | HIGH | 7.5 | 0.1% | Feb 27, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in... |
| CVE-2026-28364 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re... |
| CVE-2026-28363 | HIGH | 8.8 | 0.5% | Feb 27, 2026 | In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation... |
| CVE-2026-3285 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the ... |
| CVE-2026-3283 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file li... |
| CVE-2026-3282 | HIGH | 7.1 | 0.2% | Feb 27, 2026 | A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file li... |
| CVE-2026-3281 | HIGH | 7.8 | 0.2% | Feb 27, 2026 | A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conver... |
| CVE-2026-3275 | HIGH | 8.8 | 0.8% | Feb 27, 2026 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre... |
| CVE-2026-3274 | HIGH | 8.8 | 0.9% | Feb 27, 2026 | A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now