2026 CVE Vulnerabilities
45,152 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33654 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema... |
| CVE-2026-34387 | CRITICAL | 9.8 | 1.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software ... |
| CVE-2026-34374 | CRITICAL | 9.1 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met... |
| CVE-2026-4965 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu... |
| CVE-2026-4963 | CRITICAL | 10 | 0.6% | Mar 27, 2026 | A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu... |
| CVE-2026-33770 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method ... |
| CVE-2026-28369 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more... |
| CVE-2026-28368 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ... |
| CVE-2026-28367 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter... |
| CVE-2026-30533 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ... |
| CVE-2026-30532 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi... |
| CVE-2026-30530 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30302 | CRITICAL | 10 | 2.0% | Mar 27, 2026 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli... |
| CVE-2026-30304 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al... |
| CVE-2026-30303 | CRITICAL | 9.8 | 1.4% | Mar 27, 2026 | The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se... |
| CVE-2026-27876 | CRITICAL | 9.1 | 1.9% | Mar 27, 2026 | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac... |
| CVE-2026-1496 | CRITICAL | 9.3 | 0.5% | Mar 27, 2026 | Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ... |
| CVE-2026-4622 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4620 | CRITICAL | 9.8 | 1.0% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4619 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. |
| CVE-2026-25101 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft... |
| CVE-2026-33280 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr... |
| CVE-2026-32669 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c... |
| CVE-2026-27650 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit... |
| CVE-2026-22738 | CRITICAL | 9.8 | 0.8% | Mar 27, 2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now