2026 CVE Vulnerabilities
45,440 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31957 | CRITICAL | 10 | 0.5% | Mar 11, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelbl... |
| CVE-2026-31900 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo... |
| CVE-2026-31896 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exist... |
| CVE-2026-27703 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2026-27478 | CRITICAL | 9.1 | 0.2% | Mar 11, 2026 | Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu... |
| CVE-2026-31881 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin... |
| CVE-2026-31877 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce... |
| CVE-2026-31874 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the ... |
| CVE-2026-31975 | CRITICAL | 9.8 | 3.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31871 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31856 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection ... |
| CVE-2026-31852 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulner... |
| CVE-2026-31840 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised... |
| CVE-2026-30741 | CRITICAL | 9.8 | 0.8% | Mar 11, 2026 | A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary c... |
| CVE-2026-30903 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth... |
| CVE-2026-3944 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code... |
| CVE-2026-3826 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to exe... |
| CVE-2026-2631 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows a... |
| CVE-2026-27842 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication an... |
| CVE-2026-24448 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administr... |
| CVE-2026-29515 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all... |
| CVE-2026-23813 | CRITICAL | 9.8 | 0.7% | Mar 11, 2026 | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allo... |
| CVE-2026-31800 | CRITICAL | 9.1 | 0.3% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-30966 | CRITICAL | 10 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now