2026 CVE Vulnerabilities
67,113 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4953 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/... |
| CVE-2026-33766 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga... |
| CVE-2026-33764 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp... |
| CVE-2026-33763 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre... |
| CVE-2026-33761 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t... |
| CVE-2026-33759 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph... |
| CVE-2026-33758 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h... |
| CVE-2026-33757 | HIGH | 8.3 | 0.4% | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ... |
| CVE-2026-33755 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, a... |
| CVE-2026-33750 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, ... |
| CVE-2026-33748 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P... |
| CVE-2026-33433 | HIGH | 8.8 | 0.5% | Mar 27, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField... |
| CVE-2026-33284 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL... |
| CVE-2026-33206 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-33205 | MEDIUM | 5.5 | 0.2% | Mar 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-30689 | MEDIUM | 4.3 | 0.4% | Mar 27, 2026 | In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive ... |
| CVE-2026-30637 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b... |
| CVE-2026-30407 | — | — | — | Mar 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-30304 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al... |
| CVE-2026-30303 | CRITICAL | 9.8 | 1.4% | Mar 27, 2026 | The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se... |
| CVE-2026-29871 | HIGH | 7.5 | 0.6% | Mar 27, 2026 | A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251... |
| CVE-2026-28375 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A testdata data-source can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-27880 | HIGH | 7.5 | 0.8% | Mar 27, 2026 | The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra... |
| CVE-2026-27879 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A resample query can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-27877 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now