2026 CVE Vulnerabilities
45,451 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22453 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects... |
| CVE-2026-22451 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This ... |
| CVE-2026-22417 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This is... |
| CVE-2026-22390 | CRITICAL | 9.9 | 0.5% | Mar 5, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b... |
| CVE-2026-3381 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib incl... |
| CVE-2026-3257 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl emb... |
| CVE-2026-2835 | CRITICAL | 9.1 | 0.7% | Mar 5, 2026 | An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding ... |
| CVE-2026-2833 | CRITICAL | 9.1 | 0.7% | Mar 5, 2026 | An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The i... |
| CVE-2026-29045 | CRITICAL | 9.8 | 0.4% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin... |
| CVE-2026-26002 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4... |
| CVE-2026-29000 | CRITICAL | 9.3 | 5.9% | Mar 4, 2026 | pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator w... |
| CVE-2026-3545 | CRITICAL | 9.6 | 0.3% | Mar 4, 2026 | Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti... |
| CVE-2026-20131 | CRITICAL | 10 | 27.6% | Mar 4, 2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al... |
| CVE-2026-20079 | CRITICAL | 10 | 38.7% | Mar 4, 2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti... |
| CVE-2026-28783 | CRITICAL | 9.1 | 0.5% | Mar 4, 2026 | Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to... |
| CVE-2026-28697 | CRITICAL | 9.1 | 1.1% | Mar 4, 2026 | Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can ... |
| CVE-2026-26478 | CRITICAL | 9.8 | 2.0% | Mar 4, 2026 | A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attac... |
| CVE-2026-27446 | CRITICAL | 9.8 | 10.0% | Mar 4, 2026 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unau... |
| CVE-2026-27441 | CRITICAL | 9.8 | 0.3% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS ... |
| CVE-2026-29119 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insec... |
| CVE-2026-28778 | CRITICAL | 9.8 | 0.8% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/ins... |
| CVE-2026-28777 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account.... |
| CVE-2026-28776 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for th... |
| CVE-2026-28775 | CRITICAL | 9.8 | 1.2% | Mar 4, 2026 | An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor... |
| CVE-2026-3266 | CRITICAL | 9.8 | 0.3% | Mar 3, 2026 | Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauth... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now