2026 CVE Vulnerabilities
67,100 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4248 | HIGH | 8 | 0.2% | Mar 27, 2026 | The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl... |
| CVE-2026-33996 | MEDIUM | 5.5 | 0.1% | Mar 27, 2026 | LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS ... |
| CVE-2026-33994 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39... |
| CVE-2026-33993 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t... |
| CVE-2026-33992 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e... |
| CVE-2026-33991 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php... |
| CVE-2026-33936 | MEDIUM | 5.3 | 0.5% | Mar 27, 2026 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El... |
| CVE-2026-4990 | HIGH | 7.3 | 0.4% | Mar 27, 2026 | A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the ... |
| CVE-2026-4988 | MEDIUM | 5.9 | 0.6% | Mar 27, 2026 | A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6... |
| CVE-2026-4985 | MEDIUM | 5.3 | 0.5% | Mar 27, 2026 | A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the ... |
| CVE-2026-34226 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9... |
| CVE-2026-33989 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp... |
| CVE-2026-33981 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include... |
| CVE-2026-33980 | HIGH | 8.1 | 0.4% | Mar 27, 2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL querie... |
| CVE-2026-33979 | HIGH | 8.2 | 0.4% | Mar 27, 2026 | Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.hea... |
| CVE-2026-33976 | CRITICAL | 9.6 | 0.7% | Mar 27, 2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We... |
| CVE-2026-33955 | HIGH | 8.6 | 0.3% | Mar 27, 2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in t... |
| CVE-2026-33954 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-... |
| CVE-2026-33953 | HIGH | 8.5 | 0.3% | Mar 27, 2026 | LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP l... |
| CVE-2026-33946 | MEDIUM | 5.9 | 0.5% | Mar 27, 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S... |
| CVE-2026-33943 | CRITICAL | 9.8 | 0.8% | Mar 27, 2026 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro... |
| CVE-2026-33941 | HIGH | 8.2 | 0.3% | Mar 27, 2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand... |
| CVE-2026-33940 | HIGH | 8.1 | 0.7% | Mar 27, 2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafte... |
| CVE-2026-33939 | HIGH | 7.5 | 0.6% | Mar 27, 2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H... |
| CVE-2026-27309 | HIGH | 7.8 | 0.2% | Mar 27, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now