2026 CVE Vulnerabilities
45,193 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33640 | CRITICAL | 9.8 | 0.5% | Mar 26, 2026 | Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n... |
| CVE-2026-30458 | CRITICAL | 9.1 | 0.4% | Mar 26, 2026 | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt... |
| CVE-2026-30457 | CRITICAL | 9.8 | 0.7% | Mar 26, 2026 | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via ... |
| CVE-2026-26213 | CRITICAL | 9.8 | 6.2% | Mar 26, 2026 | thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner... |
| CVE-2026-33494 | CRITICAL | 10 | 0.5% | Mar 26, 2026 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o... |
| CVE-2026-27816 | CRITICAL | 9.1 | 0.2% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_tra... |
| CVE-2026-27815 | CRITICAL | 9.1 | 0.3% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup cop... |
| CVE-2026-33396 | CRITICAL | 9.9 | 0.8% | Mar 26, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica... |
| CVE-2026-4809 | CRITICAL | 9.8 | 1.3% | Mar 26, 2026 | plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac... |
| CVE-2026-4850 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the f... |
| CVE-2026-33942 | CRITICAL | 9.8 | 0.6% | Mar 26, 2026 | Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's un... |
| CVE-2026-33183 | CRITICAL | 9.1 | 0.6% | Mar 26, 2026 | Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names... |
| CVE-2026-30975 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affect... |
| CVE-2026-33749 | CRITICAL | 9 | 0.2% | Mar 25, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated use... |
| CVE-2026-32573 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test... |
| CVE-2026-32539 | CRITICAL | 9.3 | 0.2% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi... |
| CVE-2026-32536 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-download... |
| CVE-2026-32525 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder all... |
| CVE-2026-32524 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web S... |
| CVE-2026-32523 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious... |
| CVE-2026-32520 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalati... |
| CVE-2026-32519 | CRITICAL | 9 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affect... |
| CVE-2026-32512 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows... |
| CVE-2026-32502 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object ... |
| CVE-2026-32499 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatB... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now