2026 CVE Vulnerabilities
56,208 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2004 | HIGH | 8.8 | 0.8% | Feb 12, 2026 | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre... |
| CVE-2026-1320 | HIGH | 7.2 | 0.3% | Feb 12, 2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-1316 | HIGH | 7.2 | 0.3% | Feb 12, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].... |
| CVE-2026-2327 | HIGH | 7.5 | 0.5% | Feb 12, 2026 | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service... |
| CVE-2026-2391 | HIGH | 7.5 | 0.5% | Feb 12, 2026 | ### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabl... |
| CVE-2026-25676 | HIGH | 7.8 | 0.2% | Feb 12, 2026 | The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely l... |
| CVE-2026-26235 | HIGH | 8.7 | 1.8% | Feb 12, 2026 | JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remo... |
| CVE-2026-26234 | HIGH | 8.8 | 0.5% | Feb 12, 2026 | JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attacke... |
| CVE-2026-23857 | HIGH | 8.2 | 0.1% | Feb 12, 2026 | Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient P... |
| CVE-2026-23856 | HIGH | 7.8 | 0.1% | Feb 12, 2026 | Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, v... |
| CVE-2026-0969 | HIGH | 8.8 | 0.6% | Feb 12, 2026 | The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insuffici... |
| CVE-2026-20700 | HIGH | 7.8 | 1.3% | Feb 11, 2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3,... |
| CVE-2026-20667 | HIGH | 8.8 | 0.1% | Feb 11, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4,... |
| CVE-2026-20660 | HIGH | 7.5 | 0.8% | Feb 11, 2026 | A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.... |
| CVE-2026-20658 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An... |
| CVE-2026-20652 | HIGH | 7.5 | 0.6% | Feb 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,... |
| CVE-2026-20650 | HIGH | 7.5 | 0.5% | Feb 11, 2026 | A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS... |
| CVE-2026-20649 | HIGH | 7.5 | 0.2% | Feb 11, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe... |
| CVE-2026-20641 | HIGH | 7.1 | 0.1% | Feb 11, 2026 | A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iP... |
| CVE-2026-20628 | HIGH | 7.1 | 0.1% | Feb 11, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS... |
| CVE-2026-20626 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, ma... |
| CVE-2026-20620 | HIGH | 7.7 | 0.2% | Feb 11, 2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, m... |
| CVE-2026-20617 | HIGH | 7 | 0.1% | Feb 11, 2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequ... |
| CVE-2026-20616 | HIGH | 8.8 | 0.5% | Feb 11, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 1... |
| CVE-2026-20615 | HIGH | 7.8 | 0.2% | Feb 11, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Seq... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now