2026 CVE Vulnerabilities
67,113 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28368 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ... |
| CVE-2026-28367 | CRITICAL | 9.1 | 0.7% | Mar 27, 2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter... |
| CVE-2026-4959 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/applica... |
| CVE-2026-4958 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s... |
| CVE-2026-32984 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed... |
| CVE-2026-32983 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i... |
| CVE-2026-30534 | HIGH | 8.3 | 0.3% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via... |
| CVE-2026-30533 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ... |
| CVE-2026-30532 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi... |
| CVE-2026-30531 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30530 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30529 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30527 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ... |
| CVE-2026-30302 | CRITICAL | 10 | 2.0% | Mar 27, 2026 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli... |
| CVE-2026-5027 | HIGH | 8.8 | 31.4% | Mar 27, 2026 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an a... |
| CVE-2026-5026 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without... |
| CVE-2026-5025 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log... |
| CVE-2026-5022 | MEDIUM | 5.3 | 0.2% | Mar 27, 2026 | The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a... |
| CVE-2026-5010 | MEDIUM | 5.1 | 0.3% | Mar 27, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attac... |
| CVE-2026-4984 | HIGH | 8.2 | 0.2% | Mar 27, 2026 | The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When ... |
| CVE-2026-4980 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at... |
| CVE-2026-4957 | LOW | 2.7 | 0.3% | Mar 27, 2026 | A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of ... |
| CVE-2026-4956 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown f... |
| CVE-2026-4955 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the... |
| CVE-2026-4954 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now