2026 CVE Vulnerabilities
45,294 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4499 | CRITICAL | 9.8 | 3.2% | Mar 20, 2026 | A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex... |
| CVE-2026-4497 | CRITICAL | 9.8 | 1.9% | Mar 20, 2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad... |
| CVE-2026-32710 | CRITICAL | 9.9 | 0.9% | Mar 20, 2026 | MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 befo... |
| CVE-2026-22901 | CRITICAL | 9.8 | 0.9% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, th... |
| CVE-2026-22900 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exp... |
| CVE-2026-22898 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers c... |
| CVE-2026-22897 | CRITICAL | 9.8 | 1.1% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vul... |
| CVE-2026-22172 | CRITICAL | 9.9 | 0.5% | Mar 20, 2026 | OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that al... |
| CVE-2026-33131 | CRITICAL | 9.1 | 0.4% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in t... |
| CVE-2026-33128 | CRITICAL | 10 | 0.5% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream i... |
| CVE-2026-33067 | CRITICAL | 9 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, ... |
| CVE-2026-33066 | CRITICAL | 9 | 0.6% | Mar 20, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lu... |
| CVE-2026-33057 | CRITICAL | 9.8 | 5.3% | Mar 20, 2026 | Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explic... |
| CVE-2026-33054 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Pat... |
| CVE-2026-4473 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown proce... |
| CVE-2026-32768 | CRITICAL | 9.9 | 0.3% | Mar 20, 2026 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, ... |
| CVE-2026-4472 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability a... |
| CVE-2026-4471 | CRITICAL | 9.8 | 0.4% | Mar 20, 2026 | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ... |
| CVE-2026-4470 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is s... |
| CVE-2026-4469 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability i... |
| CVE-2026-33024 | CRITICAL | 9.1 | 0.4% | Mar 20, 2026 | AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) ... |
| CVE-2026-33017 | CRITICAL | 9.8 | 98.4% | Mar 20, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api... |
| CVE-2026-4038 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due ... |
| CVE-2026-32945 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based... |
| CVE-2026-32891 | CRITICAL | 9 | 0.2% | Mar 20, 2026 | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now