2026 CVE Vulnerabilities
67,062 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29597 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us... |
| CVE-2026-21712 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform... |
| CVE-2026-5165 | HIGH | 7.8 | 0.1% | Mar 30, 2026 | A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it... |
| CVE-2026-5164 | MEDIUM | 5.5 | 0.1% | Mar 30, 2026 | A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid... |
| CVE-2026-5122 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg... |
| CVE-2026-33373 | HIGH | 8.8 | 0.2% | Mar 30, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability e... |
| CVE-2026-30566 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30565 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30564 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30563 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerabi... |
| CVE-2026-30082 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngE... |
| CVE-2026-3321 | HIGH | 8.7 | 0.3% | Mar 30, 2026 | A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME... |
| CVE-2026-28528 | MEDIUM | 4.6 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET... |
| CVE-2026-28527 | HIGH | 7.3 | 0.2% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY... |
| CVE-2026-28526 | MEDIUM | 5.7 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA... |
| CVE-2026-4315 | MEDIUM | 6.5 | 0.2% | Mar 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t... |
| CVE-2026-4266 | MEDIUM | 6.7 | 0.3% | Mar 30, 2026 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to... |
| CVE-2026-4425 | — | — | — | Mar 30, 2026 | Rejected reason: Reserved for EastLink case, but no need for CVE anymore |
| CVE-2026-1612 | MEDIUM | 6.9 | 0.4% | Mar 30, 2026 | AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket... |
| CVE-2026-5128 | — | — | — | Mar 30, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-5121 | HIGH | 7.5 | — | Mar 30, 2026 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ... |
| CVE-2026-4416 | HIGH | 8.5 | 0.2% | Mar 30, 2026 | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate... |
| CVE-2026-4415 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena... |
| CVE-2026-3945 | HIGH | 8.7 | 0.6% | Mar 30, 2026 | An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ... |
| CVE-2026-2328 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now