2026 CVE Vulnerabilities
56,187 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1714 | HIGH | 8.6 | 0.5% | Feb 18, 2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is... |
| CVE-2026-23599 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software fo... |
| CVE-2026-22048 | HIGH | 7.1 | 0.3% | Feb 18, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and con... |
| CVE-2026-26119 | HIGH | 8.8 | 0.8% | Feb 17, 2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-2629 | HIGH | 7.3 | 1.7% | Feb 17, 2026 | A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is ... |
| CVE-2026-2627 | HIGH | 7.8 | 0.2% | Feb 17, 2026 | A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Pr... |
| CVE-2026-2623 | HIGH | 8.8 | 0.6% | Feb 17, 2026 | A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/co... |
| CVE-2026-2621 | HIGH | 7.3 | 0.3% | Feb 17, 2026 | A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This a... |
| CVE-2026-23595 | HIGH | 8.8 | 0.3% | Feb 17, 2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote at... |
| CVE-2026-2620 | HIGH | 7.3 | 0.3% | Feb 17, 2026 | A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown ... |
| CVE-2026-22284 | HIGH | 7.2 | 0.9% | Feb 17, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements use... |
| CVE-2026-2630 | HIGH | 8.8 | 1.2% | Feb 17, 2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the und... |
| CVE-2026-26736 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 pa... |
| CVE-2026-26732 | HIGH | 8.8 | 0.3% | Feb 17, 2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPas... |
| CVE-2026-26731 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`param... |
| CVE-2026-24734 | HIGH | 7.5 | 0.5% | Feb 17, 2026 | Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na... |
| CVE-2026-2618 | HIGH | 7.4 | 0.3% | Feb 17, 2026 | A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se... |
| CVE-2026-23648 | HIGH | 8.5 | 0.1% | Feb 17, 2026 | Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss... |
| CVE-2026-2617 | HIGH | 8.8 | 0.6% | Feb 17, 2026 | A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Serv... |
| CVE-2026-25087 | HIGH | 7 | 0.8% | Feb 17, 2026 | Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It ca... |
| CVE-2026-2615 | HIGH | 7.3 | 10.3% | Feb 17, 2026 | A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete... |
| CVE-2026-2247 | HIGH | 8.3 | 0.2% | Feb 17, 2026 | SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a prev... |
| CVE-2026-1216 | HIGH | 7.2 | 0.2% | Feb 17, 2026 | The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in ... |
| CVE-2026-2592 | HIGH | 7.7 | 0.3% | Feb 17, 2026 | The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd... |
| CVE-2026-2474 | HIGH | 7.5 | 0.3% | Feb 16, 2026 | Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now