2026 CVE Vulnerabilities
45,376 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22171 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr... |
| CVE-2026-27459 | CRITICAL | 9.8 | 0.7% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u... |
| CVE-2026-3856 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an... |
| CVE-2026-21994 | CRITICAL | 9.8 | 0.4% | Mar 17, 2026 | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P... |
| CVE-2026-32841 | CRITICAL | 9.2 | 0.6% | Mar 17, 2026 | Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen... |
| CVE-2026-3207 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. |
| CVE-2026-4319 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-32298 | CRITICAL | 9.1 | 0.6% | Mar 17, 2026 | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen... |
| CVE-2026-32297 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ... |
| CVE-2026-32295 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. |
| CVE-2026-32292 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede... |
| CVE-2026-25769 | CRITICAL | 9.1 | 9.2% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1... |
| CVE-2026-25534 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri... |
| CVE-2026-3564 | CRITICAL | 9 | 0.4% | Mar 17, 2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ... |
| CVE-2026-4312 | CRITICAL | 9.8 | 0.4% | Mar 17, 2026 | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remot... |
| CVE-2026-4177 | CRITICAL | 9.1 | 0.4% | Mar 16, 2026 | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap ... |
| CVE-2026-32267 | CRITICAL | 9.8 | 7.7% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R... |
| CVE-2026-28430 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera... |
| CVE-2026-4254 | CRITICAL | 9.8 | 0.9% | Mar 16, 2026 | A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of th... |
| CVE-2026-27962 | CRITICAL | 9.1 | 0.5% | Mar 16, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injectio... |
| CVE-2026-23489 | CRITICAL | 9.1 | 0.3% | Mar 16, 2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possi... |
| CVE-2026-4252 | CRITICAL | 9.8 | 1.3% | Mar 16, 2026 | A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the com... |
| CVE-2026-4228 | CRITICAL | 9.8 | 5.2% | Mar 16, 2026 | A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wi... |
| CVE-2026-4226 | CRITICAL | 9.8 | 0.7% | Mar 16, 2026 | A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /... |
| CVE-2026-4223 | CRITICAL | 9.8 | 0.4% | Mar 16, 2026 | A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now