2026 CVE Vulnerabilities
45,220 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25031 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This iss... |
| CVE-2026-25030 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affe... |
| CVE-2026-25029 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KI... |
| CVE-2026-24993 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced... |
| CVE-2026-24989 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.Thi... |
| CVE-2026-24971 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issu... |
| CVE-2026-24968 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue aff... |
| CVE-2026-24378 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Obje... |
| CVE-2026-22507 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affec... |
| CVE-2026-22500 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Inj... |
| CVE-2026-22484 | CRITICAL | 9.3 | 0.4% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Co... |
| CVE-2026-26833 | CRITICAL | 9.8 | 2.3% | Mar 25, 2026 | thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun... |
| CVE-2026-26832 | CRITICAL | 9.8 | 1.7% | Mar 25, 2026 | node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, t... |
| CVE-2026-26831 | CRITICAL | 9.8 | 2.4% | Mar 25, 2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr... |
| CVE-2026-26830 | CRITICAL | 9.8 | 2.5% | Mar 25, 2026 | pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGe... |
| CVE-2026-4784 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /chec... |
| CVE-2026-28858 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote... |
| CVE-2026-28827 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2026-20688 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Seq... |
| CVE-2026-24159 | CRITICAL | 9.8 | 0.6% | Mar 24, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit o... |
| CVE-2026-24157 | CRITICAL | 9.8 | 0.6% | Mar 24, 2026 | NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution... |
| CVE-2026-33511 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97... |
| CVE-2026-33322 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-... |
| CVE-2026-33768 | CRITICAL | 9.1 | 0.3% | Mar 24, 2026 | Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head... |
| CVE-2026-33409 | CRITICAL | 9.1 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now