2026 CVE Vulnerabilities
67,075 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28528 | MEDIUM | 4.6 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET... |
| CVE-2026-28527 | HIGH | 7.3 | 0.2% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY... |
| CVE-2026-28526 | MEDIUM | 5.7 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA... |
| CVE-2026-4315 | MEDIUM | 6.5 | 0.2% | Mar 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t... |
| CVE-2026-4266 | MEDIUM | 6.7 | 0.3% | Mar 30, 2026 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to... |
| CVE-2026-4425 | — | — | — | Mar 30, 2026 | Rejected reason: Reserved for EastLink case, but no need for CVE anymore |
| CVE-2026-1612 | MEDIUM | 6.9 | 0.4% | Mar 30, 2026 | AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket... |
| CVE-2026-5128 | — | — | — | Mar 30, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-5121 | HIGH | 7.5 | — | Mar 30, 2026 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ... |
| CVE-2026-4416 | HIGH | 8.5 | 0.2% | Mar 30, 2026 | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate... |
| CVE-2026-4415 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena... |
| CVE-2026-3945 | HIGH | 8.7 | 0.6% | Mar 30, 2026 | An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ... |
| CVE-2026-2328 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i... |
| CVE-2026-25704 | MEDIUM | 5.8 | 0.1% | Mar 30, 2026 | A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in cosmic-greete... |
| CVE-2026-5119 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies ... |
| CVE-2026-5107 | MEDIUM | 4.2 | 0.3% | Mar 30, 2026 | A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file ... |
| CVE-2026-5106 | MEDIUM | 4.8 | 0.2% | Mar 30, 2026 | A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file... |
| CVE-2026-5105 | HIGH | 8.8 | 3.7% | Mar 30, 2026 | A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassC... |
| CVE-2026-5104 | HIGH | 8.8 | 2.5% | Mar 30, 2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStatic... |
| CVE-2026-5103 | HIGH | 8.8 | 3.6% | Mar 30, 2026 | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of ... |
| CVE-2026-3124 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... |
| CVE-2026-5102 | HIGH | 8.8 | 2.2% | Mar 30, 2026 | A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function s... |
| CVE-2026-2370 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2026-5101 | HIGH | 8.8 | 2.2% | Mar 29, 2026 | A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the fil... |
| CVE-2026-4176 | CRITICAL | 9.8 | 0.7% | Mar 29, 2026 | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now