2026 CVE Vulnerabilities
67,109 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33884 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic... |
| CVE-2026-33883 | MEDIUM | 6.1 | 0.1% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:re... |
| CVE-2026-33882 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown... |
| CVE-2026-33881 | HIGH | 7.2 | 0.4% | Mar 27, 2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace env... |
| CVE-2026-33879 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation... |
| CVE-2026-33875 | CRITICAL | 9.3 | 0.3% | Mar 27, 2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 ar... |
| CVE-2026-33874 | HIGH | 7.8 | 0.3% | Mar 27, 2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 ... |
| CVE-2026-33873 | CRITICAL | 9.9 | 1.4% | Mar 27, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assis... |
| CVE-2026-32187 | — | — | — | Mar 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-4975 | HIGH | 8.8 | 0.6% | Mar 27, 2026 | A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcf... |
| CVE-2026-4974 | HIGH | 8.8 | 0.6% | Mar 27, 2026 | A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /gofor... |
| CVE-2026-4973 | LOW | 3.5 | 0.2% | Mar 27, 2026 | A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknow... |
| CVE-2026-4972 | LOW | 2.4 | 0.2% | Mar 27, 2026 | A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown fun... |
| CVE-2026-4971 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip... |
| CVE-2026-34475 | CRITICAL | 9.8 | 0.2% | Mar 27, 2026 | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR... |
| CVE-2026-34391 | HIGH | 7.5 | 0.2% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command process... |
| CVE-2026-34389 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w... |
| CVE-2026-34388 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Laun... |
| CVE-2026-34205 | CRITICAL | 9.6 | 0.3% | Mar 27, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f... |
| CVE-2026-33872 | HIGH | 7.1 | 0.3% | Mar 27, 2026 | elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results i... |
| CVE-2026-33871 | HIGH | 7.5 | 1.1% | Mar 27, 2026 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina... |
| CVE-2026-33870 | HIGH | 7.5 | 0.6% | Mar 27, 2026 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina... |
| CVE-2026-33869 | MEDIUM | 4.8 | 0.2% | Mar 27, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5... |
| CVE-2026-33868 | MEDIUM | 6.1 | 0.5% | Mar 27, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,... |
| CVE-2026-33765 | CRITICAL | 9.8 | 1.1% | Mar 27, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now