2026 CVE Vulnerabilities
56,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20615 | HIGH | 7.8 | 0.2% | Feb 11, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Seq... |
| CVE-2026-20614 | HIGH | 7.8 | 0.2% | Feb 11, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma ... |
| CVE-2026-20611 | HIGH | 7.8 | 0.3% | Feb 11, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS ... |
| CVE-2026-20610 | HIGH | 7.8 | 0.2% | Feb 11, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able... |
| CVE-2026-20606 | HIGH | 7.1 | 0.1% | Feb 11, 2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 ... |
| CVE-2026-1669 | HIGH | 7.5 | 0.3% | Feb 11, 2026 | Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp... |
| CVE-2026-26029 | HIGH | 7.5 | 0.9% | Feb 11, 2026 | sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability ex... |
| CVE-2026-26158 | HIGH | 7 | 0.2% | Feb 11, 2026 | A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di... |
| CVE-2026-26157 | HIGH | 7 | 0.7% | Feb 11, 2026 | A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf... |
| CVE-2026-26010 | HIGH | 7.6 | 0.3% | Feb 11, 2026 | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines ... |
| CVE-2026-25990 | HIGH | 7.5 | 0.4% | Feb 11, 2026 | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a... |
| CVE-2026-25924 | HIGH | 8.4 | 0.5% | Feb 11, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulner... |
| CVE-2026-25759 | HIGH | 8.7 | 0.3% | Feb 11, 2026 | Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnera... |
| CVE-2026-2321 | HIGH | 8.8 | 0.2% | Feb 11, 2026 | Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage... |
| CVE-2026-2319 | HIGH | 7.5 | 0.2% | Feb 11, 2026 | Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in spe... |
| CVE-2026-2315 | HIGH | 8.8 | 8.8% | Feb 11, 2026 | Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially ... |
| CVE-2026-2314 | HIGH | 8.8 | 4.2% | Feb 11, 2026 | Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit ... |
| CVE-2026-2313 | HIGH | 8.8 | 4.1% | Feb 11, 2026 | Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2026-2361 | HIGH | 8 | 0.3% | Feb 11, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary v... |
| CVE-2026-2360 | HIGH | 8 | 0.4% | Feb 11, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom oper... |
| CVE-2026-25869 | HIGH | 7.5 | 0.5% | Feb 11, 2026 | MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The app... |
| CVE-2026-1837 | HIGH | 7.5 | 0.2% | Feb 11, 2026 | A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after ... |
| CVE-2026-2344 | HIGH | 8.6 | 0.2% | Feb 11, 2026 | A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged use... |
| CVE-2026-2250 | HIGH | 7.5 | 0.4% | Feb 11, 2026 | The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and exp... |
| CVE-2026-2337 | HIGH | 8.7 | 0.3% | Feb 11, 2026 | A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now