2026 CVE Vulnerabilities
56,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22267 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A... |
| CVE-2026-22266 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat... |
| CVE-2026-27052 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-26362 | HIGH | 8.1 | 0.3% | Feb 19, 2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attac... |
| CVE-2026-26360 | HIGH | 8.1 | 0.3% | Feb 19, 2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p... |
| CVE-2026-26359 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p... |
| CVE-2026-26358 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacke... |
| CVE-2026-25418 | HIGH | 7.6 | 0.3% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form ... |
| CVE-2026-25378 | HIGH | 7.6 | 0.4% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel... |
| CVE-2026-25326 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25316 | HIGH | 7.2 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss... |
| CVE-2026-23805 | HIGH | 7.6 | 0.3% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media ... |
| CVE-2026-23547 | HIGH | 7.1 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit... |
| CVE-2026-23544 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects V... |
| CVE-2026-23541 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra... |
| CVE-2026-22333 | HIGH | 7.2 | 0.5% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj... |
| CVE-2026-2706 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the fil... |
| CVE-2026-2705 | HIGH | 8.1 | 0.7% | Feb 19, 2026 | A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in ... |
| CVE-2026-2704 | HIGH | 8.1 | 0.8% | Feb 19, 2026 | A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::tr... |
| CVE-2026-25474 | HIGH | 7.5 | 0.2% | Feb 19, 2026 | OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when... |
| CVE-2026-25232 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh... |
| CVE-2026-0974 | HIGH | 8.8 | 0.6% | Feb 19, 2026 | The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable ... |
| CVE-2026-0912 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc... |
| CVE-2026-25926 | HIGH | 7.3 | 0.2% | Feb 19, 2026 | Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions... |
| CVE-2026-24745 | HIGH | 7.5 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now