2026 CVE Vulnerabilities
56,102 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2644 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the lib... |
| CVE-2026-2296 | HIGH | 7.2 | 0.6% | Feb 18, 2026 | The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injec... |
| CVE-2026-2019 | HIGH | 7.2 | 0.5% | Feb 18, 2026 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl... |
| CVE-2026-1937 | HIGH | 7.2 | 0.4% | Feb 18, 2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that ... |
| CVE-2026-1368 | HIGH | 7.5 | 1.2% | Feb 18, 2026 | The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification ... |
| CVE-2026-2576 | HIGH | 7.5 | 0.4% | Feb 18, 2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based ... |
| CVE-2026-1931 | HIGH | 7.2 | 0.3% | Feb 18, 2026 | The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers... |
| CVE-2026-1714 | HIGH | 8.6 | 0.5% | Feb 18, 2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is... |
| CVE-2026-23599 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software fo... |
| CVE-2026-22048 | HIGH | 7.1 | 0.3% | Feb 18, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and con... |
| CVE-2026-26119 | HIGH | 8.8 | 0.8% | Feb 17, 2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-2629 | HIGH | 7.3 | 1.7% | Feb 17, 2026 | A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is ... |
| CVE-2026-2627 | HIGH | 7.8 | 0.2% | Feb 17, 2026 | A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Pr... |
| CVE-2026-2623 | HIGH | 8.8 | 0.6% | Feb 17, 2026 | A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/co... |
| CVE-2026-2621 | HIGH | 7.3 | 0.3% | Feb 17, 2026 | A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This a... |
| CVE-2026-23595 | HIGH | 8.8 | 0.3% | Feb 17, 2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote at... |
| CVE-2026-2620 | HIGH | 7.3 | 0.3% | Feb 17, 2026 | A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown ... |
| CVE-2026-22284 | HIGH | 7.2 | 0.9% | Feb 17, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements use... |
| CVE-2026-2630 | HIGH | 8.8 | 1.2% | Feb 17, 2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the und... |
| CVE-2026-26736 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 pa... |
| CVE-2026-26732 | HIGH | 8.8 | 0.3% | Feb 17, 2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPas... |
| CVE-2026-26731 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`param... |
| CVE-2026-24734 | HIGH | 7.5 | 0.5% | Feb 17, 2026 | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na... |
| CVE-2026-2618 | HIGH | 7.4 | 0.3% | Feb 17, 2026 | A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se... |
| CVE-2026-23648 | HIGH | 8.5 | 0.1% | Feb 17, 2026 | Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now