2026 CVE Vulnerabilities
56,318 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25027 | HIGH | 7.5 | 0.3% | Feb 3, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25022 | HIGH | 8.5 | 0.2% | Feb 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi... |
| CVE-2026-24954 | HIGH | 8.8 | 0.4% | Feb 3, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2026-1285 | HIGH | 7.5 | 1.0% | Feb 3, 2026 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char... |
| CVE-2026-1730 | HIGH | 8.8 | 0.5% | Feb 3, 2026 | The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i... |
| CVE-2026-1375 | HIGH | 8.1 | 0.3% | Feb 3, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-22550 | HIGH | 8.8 | 1.7% | Feb 3, 2026 | OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may l... |
| CVE-2026-1065 | HIGH | 7.2 | 0.3% | Feb 3, 2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc... |
| CVE-2026-1058 | HIGH | 7.1 | 0.3% | Feb 3, 2026 | The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions... |
| CVE-2026-0617 | HIGH | 7.2 | 0.4% | Feb 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-24694 | HIGH | 8.4 | 0.1% | Feb 3, 2026 | The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could ... |
| CVE-2026-0383 | HIGH | 7.8 | 0.2% | Feb 3, 2026 | A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash she... |
| CVE-2026-25222 | HIGH | 7.5 | 0.4% | Feb 2, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in ... |
| CVE-2026-25221 | HIGH | 8.1 | 0.2% | Feb 2, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for ... |
| CVE-2026-25134 | HIGH | 8.8 | 0.8% | Feb 2, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5... |
| CVE-2026-25060 | HIGH | 8.1 | 0.2% | Feb 2, 2026 | OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for a... |
| CVE-2026-25059 | HIGH | 8.8 | 0.6% | Feb 2, 2026 | OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability... |
| CVE-2026-24763 | HIGH | 8.8 | 4.8% | Feb 2, 2026 | OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command inje... |
| CVE-2026-24737 | HIGH | 8.1 | 0.5% | Feb 2, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acrofor... |
| CVE-2026-24051 | HIGH | 7 | 0.2% | Feb 2, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulner... |
| CVE-2026-23515 | HIGH | 8.8 | 4.2% | Feb 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulner... |
| CVE-2026-1778 | HIGH | 8.2 | 0.2% | Feb 2, 2026 | Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made b... |
| CVE-2026-1777 | HIGH | 8.5 | 0.5% | Feb 2, 2026 | The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext r... |
| CVE-2026-0924 | HIGH | 7 | 0.2% | Feb 2, 2026 | BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root ... |
| CVE-2026-22229 | HIGH | 7.2 | 1.9% | Feb 2, 2026 | A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now