2026 CVE Vulnerabilities
45,117 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5289 | CRITICAL | 9.6 | 0.3% | Apr 1, 2026 | Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the ... |
| CVE-2026-5288 | CRITICAL | 9.6 | 0.2% | Apr 1, 2026 | Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi... |
| CVE-2026-4374 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service... |
| CVE-2026-34449 | CRITICAL | 9.6 | 0.5% | Mar 31, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Ex... |
| CVE-2026-34448 | CRITICAL | 9 | 0.5% | Mar 31, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in a... |
| CVE-2026-34400 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection vi... |
| CVE-2026-1579 | CRITICAL | 9.8 | 0.9% | Mar 31, 2026 | The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s... |
| CVE-2026-4800 | CRITICAL | 9.8 | 2.6% | Mar 31, 2026 | Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variabl... |
| CVE-2026-30285 | CRITICAL | 9.8 | 0.6% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic... |
| CVE-2026-3356 | CRITICAL | 9.3 | 0.4% | Mar 31, 2026 | The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access ... |
| CVE-2026-30286 | CRITICAL | 9.8 | 0.6% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite ... |
| CVE-2026-30283 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to o... |
| CVE-2026-30282 | CRITICAL | 9 | 0.4% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri... |
| CVE-2026-30278 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica... |
| CVE-2026-34361 | CRITICAL | 9.3 | 0.3% | Mar 31, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-34359 | CRITICAL | 9.1 | 0.2% | Mar 31, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-24164 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo... |
| CVE-2026-24148 | CRITICAL | 9.4 | 0.3% | Mar 31, 2026 | NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co... |
| CVE-2026-34243 | CRITICAL | 9.8 | 2.2% | Mar 31, 2026 | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3... |
| CVE-2026-34235 | CRITICAL | 9.1 | 0.4% | Mar 31, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-boun... |
| CVE-2026-34221 | CRITICAL | 9.1 | 0.4% | Mar 31, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions... |
| CVE-2026-34220 | CRITICAL | 9.8 | 0.4% | Mar 31, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions... |
| CVE-2026-30281 | CRITICAL | 9.8 | 0.7% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files ... |
| CVE-2026-30276 | CRITICAL | 9.8 | 0.7% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in... |
| CVE-2026-34532 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now