2026 CVE Vulnerabilities
56,102 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24743 | HIGH | 7.5 | 0.2% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-2668 | HIGH | 7.3 | 0.5% | Feb 18, 2026 | A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an... |
| CVE-2026-24746 | HIGH | 7.5 | 0.3% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ... |
| CVE-2026-2666 | HIGH | 7.2 | 0.4% | Feb 18, 2026 | A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTem... |
| CVE-2026-2662 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms... |
| CVE-2026-2661 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the librar... |
| CVE-2026-23491 | HIGH | 7.5 | 1.1% | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vul... |
| CVE-2026-0875 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulner... |
| CVE-2026-0874 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vuln... |
| CVE-2026-2660 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_nam... |
| CVE-2026-22860 | HIGH | 7.5 | 0.7% | Feb 18, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check... |
| CVE-2026-2659 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTar... |
| CVE-2026-24708 | HIGH | 8.2 | 0.3% | Feb 18, 2026 | An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious ... |
| CVE-2026-2507 | HIGH | 8.7 | 0.3% | Feb 18, 2026 | When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note: Software versions ... |
| CVE-2026-23227 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use ctx->lock to protect struct v... |
| CVE-2026-23226 | HIGH | 7.8 | 0.4% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list x... |
| CVE-2026-23225 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Don't assume CID is CPU owned on mode ... |
| CVE-2026-23224 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix UAF issue for file-backed mounts w/ dire... |
| CVE-2026-23223 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: fix UAF in xchk_btree_check_block_owner We ca... |
| CVE-2026-23221 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_... |
| CVE-2026-27099 | HIGH | 8 | 0.5% | Feb 18, 2026 | Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov... |
| CVE-2026-23216 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_d... |
| CVE-2026-1426 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and ... |
| CVE-2026-2464 | HIGH | 8.7 | 0.6% | Feb 18, 2026 | Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read ... |
| CVE-2026-2653 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now