2026 CVE Vulnerabilities
45,220 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33768 | CRITICAL | 9.1 | 0.3% | Mar 24, 2026 | Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head... |
| CVE-2026-33409 | CRITICAL | 9.1 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-2417 | CRITICAL | 9.3 | 0.6% | Mar 24, 2026 | A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version ... |
| CVE-2026-33407 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/se... |
| CVE-2026-33340 | CRITICAL | 9.1 | 21.6% | Mar 24, 2026 | LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side ... |
| CVE-2026-33334 | CRITICAL | 9.6 | 0.4% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-4729 | CRITICAL | 9.8 | 0.3% | Mar 24, 2026 | Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-4725 | CRITICAL | 10 | 0.3% | Mar 24, 2026 | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 an... |
| CVE-2026-4724 | CRITICAL | 9.1 | 0.3% | Mar 24, 2026 | Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4723 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4721 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird ... |
| CVE-2026-4720 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these b... |
| CVE-2026-4717 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunde... |
| CVE-2026-4716 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in ... |
| CVE-2026-4715 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9... |
| CVE-2026-4711 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbi... |
| CVE-2026-4710 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140... |
| CVE-2026-4705 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4702 | CRITICAL | 9.8 | 0.5% | Mar 24, 2026 | JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4701 | CRITICAL | 9.8 | 0.5% | Mar 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thund... |
| CVE-2026-4700 | CRITICAL | 9.8 | 0.5% | Mar 24, 2026 | Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thu... |
| CVE-2026-4698 | CRITICAL | 9.8 | 0.8% | Mar 24, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115... |
| CVE-2026-4696 | CRITICAL | 9.8 | 0.5% | Mar 24, 2026 | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,... |
| CVE-2026-4692 | CRITICAL | 10 | 0.5% | Mar 24, 2026 | Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,... |
| CVE-2026-4691 | CRITICAL | 9.8 | 0.5% | Mar 24, 2026 | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 11... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now