2026 CVE Vulnerabilities
45,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32731 | CRITICAL | 9.9 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ... |
| CVE-2026-31972 | CRITICAL | 9.8 | 0.5% | Mar 18, 2026 | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D... |
| CVE-2026-25873 | CRITICAL | 9.8 | 1.1% | Mar 18, 2026 | OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows r... |
| CVE-2026-31967 | CRITICAL | 9.1 | 0.4% | Mar 18, 2026 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se... |
| CVE-2026-31966 | CRITICAL | 9.1 | 0.5% | Mar 18, 2026 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se... |
| CVE-2026-32633 | CRITICAL | 9.1 | 0.5% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/... |
| CVE-2026-32611 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject... |
| CVE-2026-30704 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hard... |
| CVE-2026-30703 | CRITICAL | 9.8 | 1.0% | Mar 18, 2026 | A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX... |
| CVE-2026-30702 | CRITICAL | 9.8 | 0.4% | Mar 18, 2026 | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web manag... |
| CVE-2026-30701 | CRITICAL | 9.1 | 0.4% | Mar 18, 2026 | The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure... |
| CVE-2026-29859 | CRITICAL | 9.8 | 0.5% | Mar 18, 2026 | An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra... |
| CVE-2026-25449 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affec... |
| CVE-2026-33265 | CRITICAL | 9 | 0.2% | Mar 18, 2026 | In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API. |
| CVE-2026-30884 | CRITICAL | 9.6 | 0.2% | Mar 18, 2026 | mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi... |
| CVE-2026-28500 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc... |
| CVE-2026-22171 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr... |
| CVE-2026-27459 | CRITICAL | 9.8 | 0.7% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u... |
| CVE-2026-3856 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an... |
| CVE-2026-21994 | CRITICAL | 9.8 | 0.4% | Mar 17, 2026 | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P... |
| CVE-2026-32841 | CRITICAL | 9.2 | 0.6% | Mar 17, 2026 | Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen... |
| CVE-2026-3207 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. |
| CVE-2026-4319 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-32298 | CRITICAL | 9.1 | 0.6% | Mar 17, 2026 | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen... |
| CVE-2026-32297 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now