2026 CVE Vulnerabilities
56,309 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20979 | HIGH | 7.8 | 0.1% | Feb 4, 2026 | Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary act... |
| CVE-2026-1756 | HIGH | 8.8 | 0.7% | Feb 4, 2026 | The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in... |
| CVE-2026-24512 | HIGH | 8.8 | 0.5% | Feb 3, 2026 | A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject c... |
| CVE-2026-1580 | HIGH | 8.8 | 0.5% | Feb 3, 2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation ... |
| CVE-2026-25510 | HIGH | 8.8 | 0.8% | Feb 3, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-25223 | HIGH | 7.5 | 0.8% | Feb 3, 2026 | Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability... |
| CVE-2026-25155 | HIGH | 7.1 | 0.1% | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isC... |
| CVE-2026-1811 | HIGH | 8.8 | 0.5% | Feb 3, 2026 | A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/m... |
| CVE-2026-24887 | HIGH | 8.8 | 0.6% | Feb 3, 2026 | Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to b... |
| CVE-2026-24052 | HIGH | 7.4 | 0.3% | Feb 3, 2026 | Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in it... |
| CVE-2026-1862 | HIGH | 8.8 | 0.6% | Feb 3, 2026 | Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2026-1861 | HIGH | 8.8 | 0.4% | Feb 3, 2026 | Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit... |
| CVE-2026-1810 | HIGH | 8.8 | 0.4% | Feb 3, 2026 | A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip ... |
| CVE-2026-25615 | HIGH | 7.2 | 0.5% | Feb 3, 2026 | Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668. |
| CVE-2026-25614 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. |
| CVE-2026-24149 | HIGH | 7.8 | 0.3% | Feb 3, 2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker m... |
| CVE-2026-1803 | HIGH | 8.2 | 0.6% | Feb 3, 2026 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear ... |
| CVE-2026-25503 | HIGH | 7.1 | 0.3% | Feb 3, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-25502 | HIGH | 7.8 | 0.2% | Feb 3, 2026 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ... |
| CVE-2026-25239 | HIGH | 7.5 | 0.2% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner... |
| CVE-2026-25235 | HIGH | 7.5 | 0.3% | Feb 3, 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verificati... |
| CVE-2026-1802 | HIGH | 7.3 | 2.7% | Feb 3, 2026 | A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the f... |
| CVE-2026-24773 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24669 | HIGH | 7.8 | 0.2% | Feb 3, 2026 | The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, ... |
| CVE-2026-24762 | HIGH | 7.5 | 0.2% | Feb 3, 2026 | RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now