2026 CVE Vulnerabilities
56,283 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21532 | HIGH | 8.2 | 0.8% | Feb 5, 2026 | Azure Function Information Disclosure Vulnerability |
| CVE-2026-1523 | HIGH | 8.7 | 1.1% | Feb 5, 2026 | Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vuln... |
| CVE-2026-23572 | HIGH | 7.2 | 0.3% | Feb 5, 2026 | Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an ... |
| CVE-2026-1294 | HIGH | 7.2 | 0.3% | Feb 5, 2026 | The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t... |
| CVE-2026-1953 | HIGH | 8.2 | 0.4% | Feb 5, 2026 | Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality... |
| CVE-2026-25585 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-22038 | HIGH | 8.1 | 0.4% | Feb 4, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2026-25584 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-25583 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-25582 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-25575 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path... |
| CVE-2026-25546 | HIGH | 7.8 | 0.9% | Feb 4, 2026 | Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a... |
| CVE-2026-25541 | HIGH | 7.5 | 0.6% | Feb 4, 2026 | Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer o... |
| CVE-2026-25539 | HIGH | 7.2 | 1.0% | Feb 4, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not valid... |
| CVE-2026-25538 | HIGH | 8.8 | 0.4% | Feb 4, 2026 | Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists i... |
| CVE-2026-25537 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, spe... |
| CVE-2026-25536 | HIGH | 7.1 | 0.3% | Feb 4, 2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to... |
| CVE-2026-25521 | HIGH | 8.8 | 0.3% | Feb 4, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to... |
| CVE-2026-25512 | HIGH | 8.8 | 18.5% | Feb 4, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a... |
| CVE-2026-25499 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur... |
| CVE-2026-0945 | HIGH | 8.8 | 0.2% | Feb 4, 2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff... |
| CVE-2026-25514 | HIGH | 8.8 | 0.5% | Feb 4, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr... |
| CVE-2026-25513 | HIGH | 8.8 | 0.5% | Feb 4, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr... |
| CVE-2026-25161 | HIGH | 8.8 | 0.7% | Feb 4, 2026 | Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a... |
| CVE-2026-25160 | HIGH | 7.4 | 0.2% | Feb 4, 2026 | Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now