2026 CVE Vulnerabilities
45,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32891 | CRITICAL | 9 | 0.2% | Mar 20, 2026 | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media ... |
| CVE-2026-32890 | CRITICAL | 9.6 | 0.4% | Mar 20, 2026 | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media ... |
| CVE-2026-21992 | CRITICAL | 9.8 | 1.0% | Mar 20, 2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracl... |
| CVE-2026-32817 | CRITICAL | 9.1 | 0.3% | Mar 20, 2026 | Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does... |
| CVE-2026-32771 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met... |
| CVE-2026-32769 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-wr... |
| CVE-2026-32767 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability... |
| CVE-2026-33289 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-32985 | CRITICAL | 9.8 | 1.5% | Mar 20, 2026 | Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te... |
| CVE-2026-32760 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-22732 | CRITICAL | 9.1 | 0.5% | Mar 19, 2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility... |
| CVE-2026-32754 | CRITICAL | 9.3 | 0.5% | Mar 19, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulner... |
| CVE-2026-32751 | CRITICAL | 9 | 0.8% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) ren... |
| CVE-2026-32194 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an u... |
| CVE-2026-32038 | CRITICAL | 9 | 0.3% | Mar 19, 2026 | OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to joi... |
| CVE-2026-30872 | CRITICAL | 9.8 | 2.2% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md... |
| CVE-2026-30871 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md... |
| CVE-2026-4428 | CRITICAL | 9.1 | 0.3% | Mar 19, 2026 | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rej... |
| CVE-2026-4395 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote at... |
| CVE-2026-3849 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E... |
| CVE-2026-3549 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf... |
| CVE-2026-32749 | CRITICAL | 9.1 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i... |
| CVE-2026-32191 | CRITICAL | 9.8 | 0.6% | Mar 19, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo... |
| CVE-2026-32169 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-30924 | CRITICAL | 9.6 | 0.3% | Mar 19, 2026 | qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now