2026 CVE Vulnerabilities
67,120 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27857 | HIGH | 7.5 | 0.7% | Mar 27, 2026 | Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi... |
| CVE-2026-27856 | MEDIUM | 5.9 | 0.4% | Mar 27, 2026 | Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u... |
| CVE-2026-27855 | MEDIUM | 5.9 | 0.3% | Mar 27, 2026 | Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern... |
| CVE-2026-24031 | HIGH | 8.2 | 0.4% | Mar 27, 2026 | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows... |
| CVE-2026-0394 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s... |
| CVE-2026-4948 | MEDIUM | 5.5 | 0.1% | Mar 27, 2026 | A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D... |
| CVE-2026-34353 | MEDIUM | 5.1 | 0.1% | Mar 27, 2026 | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un... |
| CVE-2026-33559 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the af... |
| CVE-2026-33366 | MEDIUM | 6.9 | 0.3% | Mar 27, 2026 | Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for... |
| CVE-2026-33280 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr... |
| CVE-2026-32678 | HIGH | 8.7 | 0.3% | Mar 27, 2026 | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi... |
| CVE-2026-32669 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c... |
| CVE-2026-27650 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit... |
| CVE-2026-22744 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo... |
| CVE-2026-22743 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe... |
| CVE-2026-22742 | HIGH | 8.6 | 0.4% | Mar 27, 2026 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo... |
| CVE-2026-22738 | CRITICAL | 9.8 | 0.8% | Mar 27, 2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ... |
| CVE-2026-4910 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an u... |
| CVE-2026-3098 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1... |
| CVE-2026-4909 | LOW | 2.4 | 0.3% | Mar 27, 2026 | A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /... |
| CVE-2026-4908 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ... |
| CVE-2026-4907 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted... |
| CVE-2026-4906 | HIGH | 8.8 | 2.6% | Mar 27, 2026 | A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof... |
| CVE-2026-33935 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att... |
| CVE-2026-33890 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now