2026 CVE Vulnerabilities
45,436 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32640 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu... |
| CVE-2026-32635 | CRITICAL | 9 | 0.3% | Mar 16, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-32626 | CRITICAL | 9.6 | 0.7% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32621 | CRITICAL | 9.9 | 0.5% | Mar 16, 2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11... |
| CVE-2026-20998 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. |
| CVE-2026-20997 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to p... |
| CVE-2026-3891 | CRITICAL | 9.8 | 0.8% | Mar 13, 2026 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and... |
| CVE-2026-32746 | CRITICAL | 9.8 | 23.7% | Mar 13, 2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ... |
| CVE-2026-32367 | CRITICAL | 9.1 | 0.4% | Mar 13, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog al... |
| CVE-2026-32306 | CRITICAL | 9.9 | 0.6% | Mar 13, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API acc... |
| CVE-2026-32304 | CRITICAL | 9.8 | 0.6% | Mar 13, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat... |
| CVE-2026-32301 | CRITICAL | 9.3 | 0.3% | Mar 13, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Sid... |
| CVE-2026-31897 | CRITICAL | 9.1 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free... |
| CVE-2026-31885 | CRITICAL | 9.4 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-A... |
| CVE-2026-31883 | CRITICAL | 9.8 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM an... |
| CVE-2026-31806 | CRITICAL | 9.8 | 0.7% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function proce... |
| CVE-2026-26954 | CRITICAL | 10 | 0.5% | Mar 13, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, whic... |
| CVE-2026-25823 | CRITICAL | 9.8 | 0.7% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25818 | CRITICAL | 9.1 | 0.1% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-23941 | CRITICAL | 9.4 | 0.5% | Mar 13, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module)... |
| CVE-2026-22192 | CRITICAL | 9.9 | 0.3% | Mar 13, 2026 | Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated att... |
| CVE-2026-1668 | CRITICAL | 9.8 | 1.0% | Mar 13, 2026 | The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out... |
| CVE-2026-3611 | CRITICAL | 10 | 5.6% | Mar 12, 2026 | The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-... |
| CVE-2026-32260 | CRITICAL | 9.8 | 1.5% | Mar 12, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exist... |
| CVE-2026-32248 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now