2026 CVE Vulnerabilities
56,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25521 | HIGH | 8.8 | 0.3% | Feb 4, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to... |
| CVE-2026-25512 | HIGH | 8.8 | 18.5% | Feb 4, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a... |
| CVE-2026-25499 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur... |
| CVE-2026-0945 | HIGH | 8.8 | 0.2% | Feb 4, 2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff... |
| CVE-2026-25514 | HIGH | 8.8 | 0.5% | Feb 4, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr... |
| CVE-2026-25513 | HIGH | 8.8 | 0.5% | Feb 4, 2026 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr... |
| CVE-2026-25161 | HIGH | 8.8 | 0.7% | Feb 4, 2026 | Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a... |
| CVE-2026-25160 | HIGH | 7.4 | 0.2% | Feb 4, 2026 | Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a... |
| CVE-2026-25157 | HIGH | 7.5 | 0.9% | Feb 4, 2026 | OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the ... |
| CVE-2026-25143 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacke... |
| CVE-2026-24884 | HIGH | 7.8 | 0.3% | Feb 4, 2026 | Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts... |
| CVE-2026-24844 | HIGH | 8.8 | 0.2% | Feb 4, 2026 | melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker... |
| CVE-2026-24843 | HIGH | 8.4 | 0.2% | Feb 4, 2026 | melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker ... |
| CVE-2026-23897 | HIGH | 7.5 | 0.6% | Feb 4, 2026 | Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apol... |
| CVE-2026-25140 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1... |
| CVE-2026-25121 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1... |
| CVE-2026-0536 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerabil... |
| CVE-2026-25532 | HIGH | 8 | 0.2% | Feb 4, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1... |
| CVE-2026-22044 | HIGH | 8.8 | 0.3% | Feb 4, 2026 | GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can ... |
| CVE-2026-21893 | HIGH | 7.2 | 1.3% | Feb 4, 2026 | n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerab... |
| CVE-2026-25056 | HIGH | 8.8 | 0.7% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge no... |
| CVE-2026-25055 | HIGH | 8.1 | 1.7% | Feb 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploade... |
| CVE-2026-23102 | HIGH | 7.1 | 0.1% | Feb 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Fix restoration of SVE contex... |
| CVE-2026-23099 | HIGH | 7.1 | 0.2% | Feb 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices... |
| CVE-2026-23098 | HIGH | 7.8 | 0.2% | Feb 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now