2026 CVE Vulnerabilities
66,948 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4317 | CRITICAL | 9.3 | 0.3% | Mar 31, 2026 | SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co... |
| CVE-2026-5201 | HIGH | 7.5 | 1.1% | Mar 31, 2026 | A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade... |
| CVE-2026-5196 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-5195 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ... |
| CVE-2026-3107 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password impo... |
| CVE-2026-3106 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionalit... |
| CVE-2026-5186 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb... |
| CVE-2026-5185 | MEDIUM | 5.3 | 0.2% | Mar 31, 2026 | A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t... |
| CVE-2026-5184 | HIGH | 8.8 | 5.8% | Mar 31, 2026 | A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file... |
| CVE-2026-3881 | MEDIUM | 5.8 | 0.3% | Mar 31, 2026 | The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, whic... |
| CVE-2026-5183 | CRITICAL | 9.8 | 5.1% | Mar 31, 2026 | A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ... |
| CVE-2026-5182 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teach... |
| CVE-2026-34881 | MEDIUM | 5 | 0.3% | Mar 31, 2026 | OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use... |
| CVE-2026-1877 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1834 | MEDIUM | 6.4 | 0.2% | Mar 31, 2026 | The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2026-5181 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un... |
| CVE-2026-5180 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code o... |
| CVE-2026-5179 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of th... |
| CVE-2026-4146 | MEDIUM | 6.1 | 0.3% | Mar 31, 2026 | The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter ... |
| CVE-2026-1797 | MEDIUM | 5.3 | 0.2% | Mar 31, 2026 | The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Ex... |
| CVE-2026-1710 | MEDIUM | 6.5 | 0.3% | Mar 31, 2026 | The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2026-5178 | HIGH | 8.8 | 3.7% | Mar 31, 2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the func... |
| CVE-2026-5177 | HIGH | 8.8 | 2.4% | Mar 31, 2026 | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function... |
| CVE-2026-34073 | MEDIUM | 5.3 | 0.2% | Mar 31, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version... |
| CVE-2026-34070 | HIGH | 7.5 | 1.2% | Mar 31, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now