2026 CVE Vulnerabilities
67,057 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28505 | CRITICAL | 10 | 0.5% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f... |
| CVE-2026-21717 | MEDIUM | 5.9 | 0.3% | Mar 30, 2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col... |
| CVE-2026-21716 | LOW | 3.3 | 0.2% | Mar 30, 2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th... |
| CVE-2026-21715 | LOW | 3.3 | 0.2% | Mar 30, 2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe... |
| CVE-2026-21714 | MEDIUM | 5.3 | 0.5% | Mar 30, 2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t... |
| CVE-2026-21713 | MEDIUM | 5.9 | 0.4% | Mar 30, 2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent... |
| CVE-2026-21711 | MEDIUM | 5.3 | 0.1% | Mar 30, 2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req... |
| CVE-2026-21710 | HIGH | 7.5 | 26.4% | Mar 30, 2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_... |
| CVE-2026-5147 | HIGH | 7.3 | 0.3% | Mar 30, 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin... |
| CVE-2026-3991 | HIGH | 7.8 | 0.2% | Mar 30, 2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 M... |
| CVE-2026-3502 | HIGH | 7.8 | 5.8% | Mar 30, 2026 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl... |
| CVE-2026-34714 | HIGH | 8.6 | 0.6% | Mar 30, 2026 | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat... |
| CVE-2026-29925 | HIGH | 7.7 | 0.3% | Mar 30, 2026 | Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php. |
| CVE-2026-29924 | HIGH | 7.6 | 0.3% | Mar 30, 2026 | Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a... |
| CVE-2026-5126 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. T... |
| CVE-2026-5125 | MEDIUM | 5.3 | 0.8% | Mar 30, 2026 | A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_... |
| CVE-2026-4046 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin... |
| CVE-2026-33032 | CRITICAL | 9.8 | 38.5% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context ... |
| CVE-2026-33030 | CRITICAL | 9.9 | 0.3% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di... |
| CVE-2026-33029 | MEDIUM | 6.5 | 0.9% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in ... |
| CVE-2026-33028 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl... |
| CVE-2026-33027 | MEDIUM | 6.5 | 0.4% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly... |
| CVE-2026-30077 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ... |
| CVE-2026-29872 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80... |
| CVE-2026-5124 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now