2026 CVE Vulnerabilities
45,452 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27971 | CRITICAL | 9.8 | 4.6% | Mar 3, 2026 | Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization ... |
| CVE-2026-26279 | CRITICAL | 9.1 | 0.8% | Mar 3, 2026 | Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== ins... |
| CVE-2026-3224 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear... |
| CVE-2026-3204 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers... |
| CVE-2026-3130 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker... |
| CVE-2026-2590 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions... |
| CVE-2026-27012 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri... |
| CVE-2026-24898 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0,... |
| CVE-2026-24848 | CRITICAL | 9.9 | 6.8% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and ea... |
| CVE-2026-3485 | CRITICAL | 9.8 | 4.7% | Mar 3, 2026 | A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This... |
| CVE-2026-3136 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allow... |
| CVE-2026-24103 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi. |
| CVE-2026-22891 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig... |
| CVE-2026-22886 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product... |
| CVE-2026-1492 | CRITICAL | 9.8 | 25.5% | Mar 3, 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2026-2628 | CRITICAL | 9.8 | 0.9% | Mar 3, 2026 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass... |
| CVE-2026-26713 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. |
| CVE-2026-26712 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. |
| CVE-2026-26711 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. |
| CVE-2026-26710 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. |
| CVE-2026-26709 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. |
| CVE-2026-0006 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead t... |
| CVE-2026-26707 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. |
| CVE-2026-26706 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. |
| CVE-2026-26705 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now