2026 CVE Vulnerabilities
66,725 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30282 | CRITICAL | 9 | 0.4% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri... |
| CVE-2026-30279 | HIGH | 8.4 | 0.2% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overw... |
| CVE-2026-30278 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica... |
| CVE-2026-30277 | HIGH | 8.4 | 0.2% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to ove... |
| CVE-2026-2123 | HIGH | 7.8 | 0.1% | Mar 31, 2026 | A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci... |
| CVE-2026-5205 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigge... |
| CVE-2026-34361 | CRITICAL | 9.3 | 0.3% | Mar 31, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-34360 | MEDIUM | 5.8 | 0.2% | Mar 31, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-34359 | CRITICAL | 9.1 | 0.2% | Mar 31, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-24165 | HIGH | 8.8 | 0.3% | Mar 31, 2026 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo... |
| CVE-2026-24164 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo... |
| CVE-2026-24154 | MEDIUM | 6.8 | 0.3% | Mar 31, 2026 | NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorre... |
| CVE-2026-24153 | MEDIUM | 5.5 | 0.1% | Mar 31, 2026 | NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful ex... |
| CVE-2026-24148 | CRITICAL | 9.4 | 0.3% | Mar 31, 2026 | NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co... |
| CVE-2026-5204 | HIGH | 8.8 | 2.5% | Mar 31, 2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/we... |
| CVE-2026-5203 | MEDIUM | 4.7 | 0.3% | Mar 31, 2026 | A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library m... |
| CVE-2026-5087 | HIGH | 7.5 | 0.3% | Mar 31, 2026 | PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi... |
| CVE-2026-4819 | MEDIUM | 6.5 | 0.2% | Mar 31, 2026 | In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users log... |
| CVE-2026-4818 | HIGH | 8.1 | 0.2% | Mar 31, 2026 | In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary priv... |
| CVE-2026-34595 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34574 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34573 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34243 | CRITICAL | 9.8 | 2.2% | Mar 31, 2026 | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3... |
| CVE-2026-34240 | HIGH | 7.5 | 0.1% | Mar 31, 2026 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou... |
| CVE-2026-34237 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now