2026 CVE Vulnerabilities
67,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34368 | MEDIUM | 5.3 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p... |
| CVE-2026-34364 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, ... |
| CVE-2026-30568 | MEDIUM | 4.8 | 0.2% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the v... |
| CVE-2026-30567 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view... |
| CVE-2026-4964 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_me... |
| CVE-2026-4963 | CRITICAL | 10 | 0.6% | Mar 27, 2026 | A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu... |
| CVE-2026-4962 | HIGH | 7 | 0.2% | Mar 27, 2026 | A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t... |
| CVE-2026-4961 | HIGH | 8.8 | 0.8% | Mar 27, 2026 | A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex o... |
| CVE-2026-4960 | HIGH | 8.8 | 0.8% | Mar 27, 2026 | A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/W... |
| CVE-2026-34411 | MEDIUM | 6.9 | 0.4% | Mar 27, 2026 | Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat... |
| CVE-2026-34362 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function i... |
| CVE-2026-34247 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` e... |
| CVE-2026-34245 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists... |
| CVE-2026-33867 | HIGH | 7.5 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass... |
| CVE-2026-33770 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method ... |
| CVE-2026-33767 | HIGH | 8.8 | 0.5% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike(... |
| CVE-2026-30576 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file... |
| CVE-2026-30575 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file... |
| CVE-2026-30574 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file... |
| CVE-2026-30571 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view... |
| CVE-2026-30570 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view... |
| CVE-2026-30569 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-28369 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more... |
| CVE-2026-28368 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ... |
| CVE-2026-28367 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now