2026 CVE Vulnerabilities
45,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33211 | CRITICAL | 9.6 | 0.6% | Mar 24, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-33202 | CRITICAL | 9.1 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33195 | CRITICAL | 9.8 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-4681 | CRITICAL | 9.3 | 0.7% | Mar 23, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili... |
| CVE-2026-32913 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom... |
| CVE-2026-3055 | CRITICAL | 9.8 | 84.0% | Mar 23, 2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory ove... |
| CVE-2026-30849 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family database... |
| CVE-2026-2298 | CRITICAL | 9.4 | 0.4% | Mar 23, 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing... |
| CVE-2026-33716 | CRITICAL | 9.4 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e... |
| CVE-2026-0898 | CRITICAL | 9 | 0.3% | Mar 23, 2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom... |
| CVE-2026-4404 | CRITICAL | 9.4 | 0.5% | Mar 23, 2026 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password ... |
| CVE-2026-33478 | CRITICAL | 10 | 13.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's... |
| CVE-2026-33352 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exis... |
| CVE-2026-33351 | CRITICAL | 9.1 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability ... |
| CVE-2026-33297 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz... |
| CVE-2026-31851 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec... |
| CVE-2026-31848 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which conta... |
| CVE-2026-4585 | CRITICAL | 9.8 | 3.3% | Mar 23, 2026 | A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects u... |
| CVE-2026-32968 | CRITICAL | 9.8 | 0.5% | Mar 23, 2026 | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exp... |
| CVE-2026-4581 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /... |
| CVE-2026-4580 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ... |
| CVE-2026-4579 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ... |
| CVE-2026-3587 | CRITICAL | 10 | 0.7% | Mar 23, 2026 | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l... |
| CVE-2026-4601 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig... |
| CVE-2026-4600 | CRITICAL | 9.1 | 0.2% | Mar 23, 2026 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now