2026 CVE Vulnerabilities
55,811 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25711 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-20895 | HIGH | 7.5 | 0.4% | Feb 27, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to... |
| CVE-2026-20791 | HIGH | 7.5 | 0.3% | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-1585 | HIGH | 8.4 | 0.1% | Feb 27, 2026 | An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 ma... |
| CVE-2026-3265 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unk... |
| CVE-2026-3264 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this is... |
| CVE-2026-28280 | HIGH | 8.7 | 0.2% | Feb 26, 2026 | osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exis... |
| CVE-2026-28279 | HIGH | 8.4 | 0.9% | Feb 26, 2026 | osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o... |
| CVE-2026-28276 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p... |
| CVE-2026-28275 | HIGH | 8.1 | 0.4% | Feb 26, 2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p... |
| CVE-2026-28274 | HIGH | 8.7 | 0.6% | Feb 26, 2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S... |
| CVE-2026-28269 | HIGH | 8.8 | 2.0% | Feb 26, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio... |
| CVE-2026-28216 | HIGH | 8.3 | 0.4% | Feb 26, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o... |
| CVE-2026-28211 | HIGH | 7.8 | 0.2% | Feb 26, 2026 | The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability ... |
| CVE-2026-28207 | HIGH | 7.3 | 0.9% | Feb 26, 2026 | Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command inj... |
| CVE-2026-27638 | HIGH | 7.1 | 0.3% | Feb 26, 2026 | Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi... |
| CVE-2026-3263 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this... |
| CVE-2026-3262 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is... |
| CVE-2026-27449 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi... |
| CVE-2026-25741 | HIGH | 7.1 | 0.3% | Feb 26, 2026 | Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo... |
| CVE-2026-22206 | HIGH | 8.8 | 0.6% | Feb 26, 2026 | SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to exe... |
| CVE-2026-22205 | HIGH | 8.7 | 0.5% | Feb 26, 2026 | SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una... |
| CVE-2026-27510 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg... |
| CVE-2026-27509 | HIGH | 8.5 | 0.5% | Feb 26, 2026 | Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat... |
| CVE-2026-27141 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now