2026 CVE Vulnerabilities
45,191 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30533 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ... |
| CVE-2026-30532 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi... |
| CVE-2026-30530 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30302 | CRITICAL | 10 | 2.0% | Mar 27, 2026 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli... |
| CVE-2026-30304 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al... |
| CVE-2026-30303 | CRITICAL | 9.8 | 1.4% | Mar 27, 2026 | The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se... |
| CVE-2026-27876 | CRITICAL | 9.1 | 1.9% | Mar 27, 2026 | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac... |
| CVE-2026-1496 | CRITICAL | 9.3 | 0.5% | Mar 27, 2026 | Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ... |
| CVE-2026-4622 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4620 | CRITICAL | 9.8 | 1.0% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4619 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. |
| CVE-2026-25101 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft... |
| CVE-2026-33280 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr... |
| CVE-2026-32669 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c... |
| CVE-2026-27650 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit... |
| CVE-2026-22738 | CRITICAL | 9.8 | 0.8% | Mar 27, 2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ... |
| CVE-2026-4908 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ... |
| CVE-2026-33890 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att... |
| CVE-2026-33747 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P... |
| CVE-2026-33729 | CRITICAL | 9.8 | 0.2% | Mar 27, 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2026-33728 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI ins... |
| CVE-2026-33718 | CRITICAL | 9.9 | 1.9% | Mar 27, 2026 | OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in ... |
| CVE-2026-33701 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I... |
| CVE-2026-33945 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to system... |
| CVE-2026-34352 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now