2026 CVE Vulnerabilities
55,812 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23939 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix... |
| CVE-2026-1565 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-1241 | HIGH | 8.7 | 0.3% | Feb 26, 2026 | The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage... |
| CVE-2026-26938 | HIGH | 7.7 | 0.3% | Feb 26, 2026 | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou... |
| CVE-2026-26937 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat... |
| CVE-2026-26936 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial ... |
| CVE-2026-26935 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi... |
| CVE-2026-26932 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service ... |
| CVE-2026-26682 | HIGH | 7.8 | 0.2% | Feb 26, 2026 | An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo... |
| CVE-2026-23750 | HIGH | 8.1 | 0.2% | Feb 26, 2026 | Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific... |
| CVE-2026-26265 | HIGH | 7.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil... |
| CVE-2026-26078 | HIGH | 7.5 | 0.2% | Feb 26, 2026 | Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_... |
| CVE-2026-3071 | HIGH | 8.4 | 0.2% | Feb 26, 2026 | Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar... |
| CVE-2026-2244 | HIGH | 8.4 | 0.2% | Feb 26, 2026 | A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid ... |
| CVE-2026-1198 | HIGH | 8.6 | 0.3% | Feb 26, 2026 | SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input valid... |
| CVE-2026-28138 | HIGH | 7.2 | 0.4% | Feb 26, 2026 | Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects... |
| CVE-2026-28136 | HIGH | 7.6 | 0.3% | Feb 26, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS ... |
| CVE-2026-1693 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu... |
| CVE-2026-25191 | HIGH | 8.4 | 0.1% | Feb 26, 2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is... |
| CVE-2026-23703 | HIGH | 8.5 | 0.1% | Feb 26, 2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability.... |
| CVE-2026-1311 | HIGH | 8.8 | 0.7% | Feb 26, 2026 | The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 ... |
| CVE-2026-1779 | HIGH | 8.1 | 0.3% | Feb 26, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in... |
| CVE-2026-27969 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with... |
| CVE-2026-27961 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior... |
| CVE-2026-27959 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now