2026 CVE Vulnerabilities
45,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30836 | CRITICAL | 10 | 0.3% | Mar 19, 2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ... |
| CVE-2026-27953 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the... |
| CVE-2026-26138 | CRITICAL | 10 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-26137 | CRITICAL | 9.9 | 0.5% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw... |
| CVE-2026-23658 | CRITICAL | 9.8 | 0.8% | Mar 19, 2026 | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ... |
| CVE-2026-32238 | CRITICAL | 9.1 | 1.9% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2026-3548 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over... |
| CVE-2026-30694 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone... |
| CVE-2026-32867 | CRITICAL | 9.8 | 0.2% | Mar 19, 2026 | OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ... |
| CVE-2026-32865 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque... |
| CVE-2026-30402 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi... |
| CVE-2026-2369 | CRITICAL | 9.1 | 0.4% | Mar 19, 2026 | A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour... |
| CVE-2026-22557 | CRITICAL | 10 | 15.6% | Mar 19, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App... |
| CVE-2026-27067 | CRITICAL | 9.1 | 0.3% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa... |
| CVE-2026-27065 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27542 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh... |
| CVE-2026-27540 | CRITICAL | 9 | 0.5% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu... |
| CVE-2026-27413 | CRITICAL | 9.3 | 0.4% | Mar 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile... |
| CVE-2026-32737 | CRITICAL | 10 | 0.4% | Mar 18, 2026 | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function... |
| CVE-2026-32731 | CRITICAL | 9.9 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ... |
| CVE-2026-31972 | CRITICAL | 9.8 | 0.5% | Mar 18, 2026 | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D... |
| CVE-2026-25873 | CRITICAL | 9.8 | 1.1% | Mar 18, 2026 | OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows r... |
| CVE-2026-31967 | CRITICAL | 9.1 | 0.4% | Mar 18, 2026 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se... |
| CVE-2026-31966 | CRITICAL | 9.1 | 0.5% | Mar 18, 2026 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se... |
| CVE-2026-32633 | CRITICAL | 9.1 | 0.5% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now