2026 CVE Vulnerabilities
67,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33868 | MEDIUM | 6.1 | 0.5% | Mar 27, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,... |
| CVE-2026-33765 | CRITICAL | 9.8 | 1.1% | Mar 27, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33739 | MEDIUM | 4.8 | 0.2% | Mar 27, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta... |
| CVE-2026-33654 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema... |
| CVE-2026-33045 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20... |
| CVE-2026-33044 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20... |
| CVE-2026-32241 | HIGH | 8.8 | 2.7% | Mar 27, 2026 | Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens... |
| CVE-2026-31951 | MEDIUM | 5.7 | 0.2% | Mar 27, 2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model ... |
| CVE-2026-31950 | MEDIUM | 5.3 | 0.2% | Mar 27, 2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi... |
| CVE-2026-31945 | HIGH | 7.7 | 0.2% | Mar 27, 2026 | LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side ... |
| CVE-2026-31943 | HIGH | 8.5 | 0.2% | Mar 27, 2026 | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth... |
| CVE-2026-4970 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the... |
| CVE-2026-4969 | LOW | 3.5 | 0.2% | Mar 27, 2026 | A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function ... |
| CVE-2026-34387 | CRITICAL | 9.8 | 1.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software ... |
| CVE-2026-34386 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap... |
| CVE-2026-34385 | HIGH | 8.1 | 0.2% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's ... |
| CVE-2026-34375 | HIGH | 8.2 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm... |
| CVE-2026-34374 | CRITICAL | 9.1 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met... |
| CVE-2026-34369 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap... |
| CVE-2026-29180 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host ... |
| CVE-2026-26061 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint... |
| CVE-2026-26060 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c... |
| CVE-2026-4968 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file ... |
| CVE-2026-4966 | MEDIUM | 6.3 | 0.3% | Mar 27, 2026 | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /ad... |
| CVE-2026-4965 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now