2026 CVE Vulnerabilities
67,062 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33028 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl... |
| CVE-2026-33027 | MEDIUM | 6.5 | 0.4% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly... |
| CVE-2026-30077 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ... |
| CVE-2026-29872 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80... |
| CVE-2026-5124 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes... |
| CVE-2026-29954 | HIGH | 7.6 | 0.3% | Mar 30, 2026 | In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th... |
| CVE-2026-29909 | MEDIUM | 5.3 | 0.4% | Mar 30, 2026 | MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/f... |
| CVE-2026-27508 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redire... |
| CVE-2026-26352 | MEDIUM | 5.4 | 0.1% | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/v... |
| CVE-2026-5170 | MEDIUM | 5.3 | 0.2% | Mar 30, 2026 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during... |
| CVE-2026-5123 | MEDIUM | 6.3 | 0.4% | Mar 30, 2026 | A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/pack... |
| CVE-2026-34472 | HIGH | 7.1 | 8.9% | Mar 30, 2026 | Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u... |
| CVE-2026-33643 | HIGH | 7.4 | 0.2% | Mar 30, 2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file pl... |
| CVE-2026-30562 | CRITICAL | 9.3 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30561 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30560 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30559 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30558 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30557 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30556 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-2287 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that... |
| CVE-2026-2286 | CRITICAL | 9.8 | 0.5% | Mar 30, 2026 | CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser... |
| CVE-2026-2285 | HIGH | 7.5 | 0.6% | Mar 30, 2026 | CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validati... |
| CVE-2026-2275 | CRITICAL | 9.6 | 0.4% | Mar 30, 2026 | The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar... |
| CVE-2026-29953 | HIGH | 7.4 | 0.2% | Mar 30, 2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now