2026 CVE Vulnerabilities
56,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27114 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf... |
| CVE-2026-26313 | HIGH | 7.5 | 0.6% | Feb 19, 2026 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta... |
| CVE-2026-26286 | HIGH | 8.5 | 0.3% | Feb 19, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-26318 | HIGH | 8.8 | 1.1% | Feb 19, 2026 | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command... |
| CVE-2026-26280 | HIGH | 7.8 | 1.2% | Feb 19, 2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v... |
| CVE-2026-26278 | HIGH | 7.5 | 0.8% | Feb 19, 2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li... |
| CVE-2026-26267 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma... |
| CVE-2026-26205 | HIGH | 7.1 | 0.4% | Feb 19, 2026 | opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i... |
| CVE-2026-26202 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c... |
| CVE-2026-26201 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access... |
| CVE-2026-26200 | HIGH | 7.8 | 0.4% | Feb 19, 2026 | HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c... |
| CVE-2026-26189 | HIGH | 8.1 | 1.3% | Feb 19, 2026 | Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne... |
| CVE-2026-26063 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack... |
| CVE-2026-26337 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s... |
| CVE-2026-2232 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v... |
| CVE-2026-26336 | HIGH | 8.7 | 0.3% | Feb 19, 2026 | Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via t... |
| CVE-2026-26016 | HIGH | 8.1 | 0.3% | Feb 19, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.... |
| CVE-2026-25998 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the datab... |
| CVE-2026-24834 | HIGH | 8.8 | 0.2% | Feb 19, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-1581 | HIGH | 7.5 | 1.7% | Feb 19, 2026 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version... |
| CVE-2026-2274 | HIGH | 8.5 | 0.3% | Feb 19, 2026 | A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authentic... |
| CVE-2026-26345 | HIGH | 8.6 | 0.2% | Feb 19, 2026 | SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edg... |
| CVE-2026-25940 | HIGH | 8.1 | 0.4% | Feb 19, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acrofor... |
| CVE-2026-25755 | HIGH | 8.8 | 0.8% | Feb 19, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method al... |
| CVE-2026-25535 | HIGH | 7.5 | 0.7% | Feb 19, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now