2026 CVE Vulnerabilities
56,318 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22227 | HIGH | 7.2 | 2.6% | Feb 2, 2026 | A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora... |
| CVE-2026-22226 | HIGH | 7.2 | 2.4% | Feb 2, 2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu... |
| CVE-2026-22225 | HIGH | 7.2 | 2.7% | Feb 2, 2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the... |
| CVE-2026-22224 | HIGH | 7.2 | 2.6% | Feb 2, 2026 | A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface... |
| CVE-2026-22223 | HIGH | 8 | 1.4% | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack... |
| CVE-2026-22222 | HIGH | 8 | 1.4% | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attack... |
| CVE-2026-22221 | HIGH | 8 | 1.3% | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack... |
| CVE-2026-0631 | HIGH | 8 | 1.3% | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjace... |
| CVE-2026-0630 | HIGH | 8 | 1.3% | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent ... |
| CVE-2026-24071 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting clie... |
| CVE-2026-24070 | HIGH | 8.8 | 0.2% | Feb 2, 2026 | During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe... |
| CVE-2026-1761 | HIGH | 8.6 | 0.9% | Feb 2, 2026 | A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP ... |
| CVE-2026-1186 | HIGH | 8.6 | 0.3% | Feb 2, 2026 | EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (defa... |
| CVE-2026-0599 | HIGH | 7.5 | 23.7% | Feb 2, 2026 | A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploi... |
| CVE-2026-1117 | HIGH | 8.2 | 0.4% | Feb 2, 2026 | A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated a... |
| CVE-2026-20412 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2026-20411 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv... |
| CVE-2026-20409 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2026-20408 | HIGH | 8.8 | 0.3% | Feb 2, 2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja... |
| CVE-2026-20401 | HIGH | 7.5 | 0.7% | Feb 2, 2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if... |
| CVE-2026-22888 | HIGH | 7.5 | 0.4% | Feb 2, 2026 | Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of p... |
| CVE-2026-1746 | HIGH | 8.8 | 0.4% | Feb 2, 2026 | A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap... |
| CVE-2026-1531 | HIGH | 8.1 | 0.3% | Feb 2, 2026 | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification... |
| CVE-2026-1530 | HIGH | 8.1 | 0.3% | Feb 2, 2026 | A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) atta... |
| CVE-2026-25201 | HIGH | 8.8 | 0.4% | Feb 2, 2026 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now