2026 CVE Vulnerabilities
56,236 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0652 | HIGH | 8.8 | 22.8% | Feb 10, 2026 | On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters ... |
| CVE-2026-0651 | HIGH | 7.8 | 0.3% | Feb 10, 2026 | A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP ser... |
| CVE-2026-24885 | HIGH | 8 | 0.2% | Feb 10, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CS... |
| CVE-2026-22153 | HIGH | 8.1 | 0.7% | Feb 10, 2026 | An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6... |
| CVE-2026-21743 | HIGH | 7.2 | 0.3% | Feb 10, 2026 | A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ver... |
| CVE-2026-1603 | HIGH | 7.5 | 81.1% | Feb 10, 2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to ... |
| CVE-2026-2268 | HIGH | 7.5 | 0.3% | Feb 10, 2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2026-25656 | HIGH | 8.5 | 0.2% | Feb 10, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All version... |
| CVE-2026-25655 | HIGH | 8.5 | 0.2% | Feb 10, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper mo... |
| CVE-2026-24343 | HIGH | 8.8 | 0.7% | Feb 10, 2026 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This is... |
| CVE-2026-23720 | HIGH | 7.3 | 0.2% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-23719 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-23718 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-23717 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-23716 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-23715 | HIGH | 7.3 | 0.2% | Feb 10, 2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).... |
| CVE-2026-22923 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected... |
| CVE-2026-1866 | HIGH | 7.2 | 0.3% | Feb 10, 2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in ... |
| CVE-2026-2097 | HIGH | 8.8 | 0.4% | Feb 10, 2026 | Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to u... |
| CVE-2026-2094 | HIGH | 8.8 | 0.3% | Feb 10, 2026 | Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi... |
| CVE-2026-2093 | HIGH | 8.7 | 0.5% | Feb 10, 2026 | Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject ar... |
| CVE-2026-2260 | HIGH | 7.3 | 5.0% | Feb 10, 2026 | A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin.... |
| CVE-2026-24322 | HIGH | 7.7 | 0.2% | Feb 10, 2026 | SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f... |
| CVE-2026-23689 | HIGH | 7.7 | 0.4% | Feb 10, 2026 | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us... |
| CVE-2026-23687 | HIGH | 8.8 | 0.5% | Feb 10, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now