2026 CVE Vulnerabilities
67,120 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30304 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al... |
| CVE-2026-30303 | CRITICAL | 9.8 | 1.4% | Mar 27, 2026 | The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se... |
| CVE-2026-29871 | HIGH | 7.5 | 0.6% | Mar 27, 2026 | A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251... |
| CVE-2026-28375 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A testdata data-source can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-27880 | HIGH | 7.5 | 0.8% | Mar 27, 2026 | The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra... |
| CVE-2026-27879 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A resample query can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-27877 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u... |
| CVE-2026-27876 | CRITICAL | 9.1 | 1.9% | Mar 27, 2026 | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac... |
| CVE-2026-1496 | CRITICAL | 9.3 | 0.5% | Mar 27, 2026 | Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ... |
| CVE-2026-32859 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts... |
| CVE-2026-32695 | HIGH | 7.7 | 0.5% | Mar 27, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider ... |
| CVE-2026-4982 | HIGH | 7.3 | 0.2% | Mar 27, 2026 | A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or... |
| CVE-2026-4340 | — | — | — | Mar 27, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-4622 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4621 | MEDIUM | 5.6 | 0.2% | Mar 27, 2026 | Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network. |
| CVE-2026-4620 | CRITICAL | 9.8 | 1.0% | Mar 27, 2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command... |
| CVE-2026-4619 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. |
| CVE-2026-4309 | MEDIUM | 6.5 | 0.1% | Mar 27, 2026 | Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor... |
| CVE-2026-25101 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft... |
| CVE-2026-25100 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker w... |
| CVE-2026-25099 | HIGH | 8.8 | 1.9% | Mar 27, 2026 | Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension wi... |
| CVE-2026-3457 | MEDIUM | 6.8 | 0.1% | Mar 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent... |
| CVE-2026-27860 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l... |
| CVE-2026-27859 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma... |
| CVE-2026-27858 | HIGH | 7.5 | 0.8% | Mar 27, 2026 | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now