2026 CVE Vulnerabilities
56,095 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25378 | HIGH | 7.6 | 0.4% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel... |
| CVE-2026-25326 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25316 | HIGH | 7.2 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss... |
| CVE-2026-23805 | HIGH | 7.6 | 0.3% | Feb 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media ... |
| CVE-2026-23547 | HIGH | 7.1 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit... |
| CVE-2026-23544 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects V... |
| CVE-2026-23541 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra... |
| CVE-2026-22333 | HIGH | 7.2 | 0.5% | Feb 19, 2026 | Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj... |
| CVE-2026-2706 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the fil... |
| CVE-2026-2705 | HIGH | 8.1 | 0.7% | Feb 19, 2026 | A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in ... |
| CVE-2026-2704 | HIGH | 8.1 | 0.8% | Feb 19, 2026 | A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::tr... |
| CVE-2026-25474 | HIGH | 7.5 | 0.2% | Feb 19, 2026 | OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when... |
| CVE-2026-25232 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh... |
| CVE-2026-0974 | HIGH | 8.8 | 0.6% | Feb 19, 2026 | The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable ... |
| CVE-2026-0912 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc... |
| CVE-2026-25926 | HIGH | 7.3 | 0.2% | Feb 19, 2026 | Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions... |
| CVE-2026-24745 | HIGH | 7.5 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-2670 | HIGH | 7.2 | 16.3% | Feb 18, 2026 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6... |
| CVE-2026-2650 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit ... |
| CVE-2026-2649 | HIGH | 8.8 | 0.6% | Feb 18, 2026 | Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap co... |
| CVE-2026-2648 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of b... |
| CVE-2026-27182 | HIGH | 8.6 | 1.2% | Feb 18, 2026 | Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute a... |
| CVE-2026-27181 | HIGH | 8.7 | 0.7% | Feb 18, 2026 | MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. ... |
| CVE-2026-24744 | HIGH | 7.5 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-24743 | HIGH | 7.5 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now