2026 CVE Vulnerabilities
67,050 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32696 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http... |
| CVE-2026-31946 | CRITICAL | 9.8 | 0.2% | Mar 30, 2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers... |
| CVE-2026-30313 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel... |
| CVE-2026-30308 | CRITICAL | 9.8 | 0.5% | Mar 30, 2026 | In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman... |
| CVE-2026-30306 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al... |
| CVE-2026-28228 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to ... |
| CVE-2026-27599 | HIGH | 7.2 | 0.4% | Mar 30, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-27018 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can ... |
| CVE-2026-25627 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc... |
| CVE-2026-5150 | HIGH | 7.3 | 0.3% | Mar 30, 2026 | A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown proce... |
| CVE-2026-5148 | MEDIUM | 4.7 | 0.3% | Mar 30, 2026 | A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file ... |
| CVE-2026-33026 | CRITICAL | 9.1 | 0.3% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism... |
| CVE-2026-32275 | CRITICAL | 9.1 | 0.3% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1... |
| CVE-2026-31831 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/... |
| CVE-2026-31804 | MEDIUM | 5.3 | 0.3% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_p... |
| CVE-2026-31799 | MEDIUM | 4.9 | 0.4% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.1... |
| CVE-2026-30307 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis... |
| CVE-2026-30305 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s... |
| CVE-2026-28505 | CRITICAL | 10 | 0.5% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f... |
| CVE-2026-21717 | MEDIUM | 5.9 | 0.3% | Mar 30, 2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col... |
| CVE-2026-21716 | LOW | 3.3 | 0.2% | Mar 30, 2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th... |
| CVE-2026-21715 | LOW | 3.3 | 0.2% | Mar 30, 2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe... |
| CVE-2026-21714 | MEDIUM | 5.3 | 0.5% | Mar 30, 2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t... |
| CVE-2026-21713 | MEDIUM | 5.9 | 0.4% | Mar 30, 2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent... |
| CVE-2026-21711 | MEDIUM | 5.3 | 0.1% | Mar 30, 2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now