2026 CVE Vulnerabilities
66,812 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5176 | CRITICAL | 9.8 | 1.9% | Mar 31, 2026 | A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of ... |
| CVE-2026-4020 | HIGH | 7.5 | 39.7% | Mar 31, 2026 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2026-3300 | CRITICAL | 9.8 | 41.0% | Mar 31, 2026 | The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions... |
| CVE-2026-5115 | HIGH | 7.5 | 0.2% | Mar 31, 2026 | The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin... |
| CVE-2026-4794 | MEDIUM | 4.8 | 0.2% | Mar 31, 2026 | Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator u... |
| CVE-2026-32734 | MEDIUM | 6.1 | 0.3% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag ... |
| CVE-2026-30940 | HIGH | 7.2 | 1.0% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme ... |
| CVE-2026-30880 | CRITICAL | 9.8 | 2.1% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ... |
| CVE-2026-30879 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability i... |
| CVE-2026-30878 | MEDIUM | 5.3 | 0.4% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated... |
| CVE-2026-30877 | HIGH | 7.2 | 1.5% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t... |
| CVE-2026-27697 | CRITICAL | 9.8 | 0.4% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ... |
| CVE-2026-21861 | HIGH | 7.2 | 2.3% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi... |
| CVE-2026-5157 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the ... |
| CVE-2026-5156 | HIGH | 8.8 | 0.6% | Mar 31, 2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/Quick... |
| CVE-2026-5155 | HIGH | 8.8 | 0.8% | Mar 30, 2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan o... |
| CVE-2026-5154 | HIGH | 8.8 | 0.6% | Mar 30, 2026 | A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /... |
| CVE-2026-5130 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up... |
| CVE-2026-5153 | HIGH | 8.8 | 3.0% | Mar 30, 2026 | A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr... |
| CVE-2026-4257 | CRITICAL | 9.8 | 41.5% | Mar 30, 2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem... |
| CVE-2026-33995 | MEDIUM | 5.3 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in... |
| CVE-2026-33987 | MEDIUM | 6.6 | 0.1% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry... |
| CVE-2026-33986 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf... |
| CVE-2026-33985 | HIGH | 7.1 | 0.2% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap ... |
| CVE-2026-33984 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now