2026 CVE Vulnerabilities
55,812 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27942 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-27938 | HIGH | 7.7 | 0.8% | Feb 26, 2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con... |
| CVE-2026-27904 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version... |
| CVE-2026-27903 | HIGH | 7.5 | 0.5% | Feb 26, 2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version... |
| CVE-2026-27900 | HIGH | 7.7 | 0.5% | Feb 26, 2026 | The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackS... |
| CVE-2026-27899 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.... |
| CVE-2026-1557 | HIGH | 7.5 | 1.7% | Feb 26, 2026 | The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 ... |
| CVE-2026-27896 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prio... |
| CVE-2026-27888 | HIGH | 7.5 | 0.3% | Feb 26, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can cra... |
| CVE-2026-27831 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Ver... |
| CVE-2026-27830 | HIGH | 8 | 0.5% | Feb 26, 2026 | c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `ja... |
| CVE-2026-27829 | HIGH | 7.2 | 0.3% | Feb 26, 2026 | Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domai... |
| CVE-2026-27976 | HIGH | 8.8 | 0.5% | Feb 26, 2026 | Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`... |
| CVE-2026-27967 | HIGH | 7.1 | 0.2% | Feb 26, 2026 | Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `e... |
| CVE-2026-27821 | HIGH | 7.8 | 0.3% | Feb 26, 2026 | GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs dur... |
| CVE-2026-27818 | HIGH | 7.5 | 0.2% | Feb 26, 2026 | TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A v... |
| CVE-2026-27808 | HIGH | 8.6 | 0.5% | Feb 26, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{I... |
| CVE-2026-27800 | HIGH | 7.4 | 0.3% | Feb 26, 2026 | Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionali... |
| CVE-2026-27798 | HIGH | 7.1 | 0.1% | Feb 26, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-27635 | HIGH | 8.8 | 0.4% | Feb 26, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-27633 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Servi... |
| CVE-2026-27630 | HIGH | 7.5 | 0.4% | Feb 26, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a De... |
| CVE-2026-26186 | HIGH | 8.8 | 0.3% | Feb 26, 2026 | Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authe... |
| CVE-2026-27498 | HIGH | 8.8 | 0.7% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with perm... |
| CVE-2026-27497 | HIGH | 8.8 | 0.8% | Feb 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now