2026 CVE Vulnerabilities
55,826 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25476 | HIGH | 7.5 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-25164 | HIGH | 8.1 | 0.3% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-24005 | HIGH | 7.6 | 0.3% | Feb 25, 2026 | Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodPr... |
| CVE-2026-23627 | HIGH | 8.8 | 0.8% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-3194 | HIGH | 7 | 0.2% | Feb 25, 2026 | A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of... |
| CVE-2026-27850 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source por... |
| CVE-2026-27795 | HIGH | 7.4 | 0.2% | Feb 25, 2026 | LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Req... |
| CVE-2026-25554 | HIGH | 8.3 | 0.3% | Feb 25, 2026 | OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vuln... |
| CVE-2026-3192 | HIGH | 8.1 | 0.5% | Feb 25, 2026 | A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of th... |
| CVE-2026-27728 | HIGH | 8.8 | 1.7% | Feb 25, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vu... |
| CVE-2026-27706 | HIGH | 7.7 | 0.2% | Feb 25, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSR... |
| CVE-2026-20133 | HIGH | 7.5 | 10.2% | Feb 25, 2026 | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive info... |
| CVE-2026-20128 | HIGH | 7.5 | 5.3% | Feb 25, 2026 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticat... |
| CVE-2026-20126 | HIGH | 7.8 | 0.3% | Feb 25, 2026 | A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gai... |
| CVE-2026-20051 | HIGH | 7.4 | 0.2% | Feb 25, 2026 | A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and... |
| CVE-2026-20048 | HIGH | 7.7 | 0.3% | Feb 25, 2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in... |
| CVE-2026-20033 | HIGH | 7.4 | 0.2% | Feb 25, 2026 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker... |
| CVE-2026-20010 | HIGH | 7.4 | 0.2% | Feb 25, 2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticat... |
| CVE-2026-27730 | HIGH | 7.5 | 0.3% | Feb 25, 2026 | esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF v... |
| CVE-2026-27704 | HIGH | 7.5 | 0.4% | Feb 25, 2026 | The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart S... |
| CVE-2026-27701 | HIGH | 8.8 | 0.3% | Feb 25, 2026 | LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveC... |
| CVE-2026-27700 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, whe... |
| CVE-2026-22866 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In ve... |
| CVE-2026-3203 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service |
| CVE-2026-3202 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now