2026 CVE Vulnerabilities
56,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22357 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link ... |
| CVE-2026-22356 | HIGH | 7.5 | 0.4% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22354 | HIGH | 8.8 | 0.5% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for... |
| CVE-2026-22352 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Pers... |
| CVE-2026-22351 | HIGH | 7.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectl... |
| CVE-2026-22346 | HIGH | 8.8 | 0.3% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slidesh... |
| CVE-2026-22345 | HIGH | 8.8 | 0.3% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery,... |
| CVE-2026-22344 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-20761 | HIGH | 8.1 | 0.9% | Feb 20, 2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th... |
| CVE-2026-26050 | HIGH | 8.4 | 0.2% | Feb 20, 2026 | The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search pat... |
| CVE-2026-2824 | HIGH | 8.8 | 9.5% | Feb 20, 2026 | A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?me... |
| CVE-2026-2823 | HIGH | 8.8 | 13.0% | Feb 20, 2026 | A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-... |
| CVE-2026-2822 | HIGH | 8.8 | 0.4% | Feb 20, 2026 | A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the ... |
| CVE-2026-2821 | HIGH | 7.3 | 0.3% | Feb 20, 2026 | A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown f... |
| CVE-2026-26996 | HIGH | 7.5 | 0.5% | Feb 20, 2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 ... |
| CVE-2026-2820 | HIGH | 7.3 | 0.3% | Feb 20, 2026 | A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects ... |
| CVE-2026-26990 | HIGH | 8.8 | 4.1% | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Bas... |
| CVE-2026-26980 | HIGH | 7.5 | 70.0% | Feb 20, 2026 | Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform ... |
| CVE-2026-26960 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-control... |
| CVE-2026-26065 | HIGH | 8.8 | 0.5% | Feb 20, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and ... |
| CVE-2026-26064 | HIGH | 8.8 | 0.9% | Feb 20, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and ... |
| CVE-2026-26975 | HIGH | 8.8 | 1.4% | Feb 20, 2026 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Vers... |
| CVE-2026-2435 | HIGH | 8.8 | 0.2% | Feb 20, 2026 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-27001 | HIGH | 7.8 | 0.2% | Feb 20, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (worksp... |
| CVE-2026-26959 | HIGH | 7.8 | 0.2% | Feb 20, 2026 | ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now