2026 CVE Vulnerabilities
66,723 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34395 | MEDIUM | 6.5 | 0.3% | Mar 31, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpo... |
| CVE-2026-34394 | HIGH | 8.1 | 0.2% | Mar 31, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (... |
| CVE-2026-34384 | HIGH | 7.3 | 0.2% | Mar 31, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_u... |
| CVE-2026-34383 | LOW | 3.5 | 0.1% | Mar 31, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint ac... |
| CVE-2026-34382 | MEDIUM | 4.6 | 0.1% | Mar 31, 2026 | Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler ... |
| CVE-2026-34381 | HIGH | 7.5 | 0.6% | Mar 31, 2026 | Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my... |
| CVE-2026-34372 | LOW | 2.7 | 0.3% | Mar 31, 2026 | Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2... |
| CVE-2026-34367 | HIGH | 8.7 | 0.3% | Mar 31, 2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and... |
| CVE-2026-34366 | HIGH | 8.1 | 0.2% | Mar 31, 2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and... |
| CVE-2026-1579 | CRITICAL | 9.8 | 0.9% | Mar 31, 2026 | The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s... |
| CVE-2026-5211 | HIGH | 8.8 | 0.7% | Mar 31, 2026 | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, D... |
| CVE-2026-4800 | CRITICAL | 9.8 | 2.8% | Mar 31, 2026 | Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variabl... |
| CVE-2026-34784 | HIGH | 7.5 | 0.4% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34365 | HIGH | 8.1 | 0.2% | Mar 31, 2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and... |
| CVE-2026-34215 | MEDIUM | 6.5 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34206 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes a... |
| CVE-2026-34204 | HIGH | 7.1 | 0.1% | Mar 31, 2026 | MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetad... |
| CVE-2026-34203 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creatio... |
| CVE-2026-30290 | HIGH | 8.4 | 0.2% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite crit... |
| CVE-2026-30285 | CRITICAL | 9.8 | 0.6% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic... |
| CVE-2026-30280 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 al... |
| CVE-2026-2950 | MEDIUM | 5.3 | 0.3% | Mar 31, 2026 | Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. ... |
| CVE-2026-5210 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a ... |
| CVE-2026-5209 | LOW | 2.4 | 0.3% | Mar 31, 2026 | A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is som... |
| CVE-2026-3356 | CRITICAL | 9.3 | 0.4% | Mar 31, 2026 | The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now