2026 CVE Vulnerabilities
56,195 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25108 | HIGH | 8.8 | 5.0% | Feb 13, 2026 | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user... |
| CVE-2026-26225 | HIGH | 8.5 | 0.2% | Feb 12, 2026 | Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones,... |
| CVE-2026-26224 | HIGH | 8.5 | 0.1% | Feb 12, 2026 | Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and applicati... |
| CVE-2026-26076 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce ... |
| CVE-2026-26069 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Re... |
| CVE-2026-26056 | HIGH | 8.8 | 0.4% | Feb 12, 2026 | Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in ... |
| CVE-2026-26055 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in ... |
| CVE-2026-26020 | HIGH | 8.8 | 0.5% | Feb 12, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2026-25949 | HIGH | 7.5 | 0.7% | Feb 12, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managi... |
| CVE-2026-25922 | HIGH | 8.8 | 0.2% | Feb 12, 2026 | authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source tha... |
| CVE-2026-25767 | HIGH | 8.1 | 0.3% | Feb 12, 2026 | LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymak... |
| CVE-2026-25748 | HIGH | 7.5 | 0.5% | Feb 12, 2026 | authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible... |
| CVE-2026-25227 | HIGH | 7.2 | 0.6% | Feb 12, 2026 | authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using de... |
| CVE-2026-24894 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO... |
| CVE-2026-21435 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of s... |
| CVE-2026-21434 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive ... |
| CVE-2026-26217 | HIGH | 7.5 | 0.6% | Feb 12, 2026 | Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute... |
| CVE-2026-1104 | HIGH | 8.8 | 0.3% | Feb 12, 2026 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creatio... |
| CVE-2026-2007 | HIGH | 8.2 | 0.5% | Feb 12, 2026 | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.... |
| CVE-2026-2006 | HIGH | 8.8 | 1.1% | Feb 12, 2026 | Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted... |
| CVE-2026-2005 | HIGH | 8.8 | 1.2% | Feb 12, 2026 | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating syst... |
| CVE-2026-2004 | HIGH | 8.8 | 0.8% | Feb 12, 2026 | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre... |
| CVE-2026-1320 | HIGH | 7.2 | 0.3% | Feb 12, 2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-1316 | HIGH | 7.2 | 0.3% | Feb 12, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].... |
| CVE-2026-2327 | HIGH | 7.5 | 0.5% | Feb 12, 2026 | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now