2026 CVE Vulnerabilities
67,127 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3098 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1... |
| CVE-2026-4909 | LOW | 2.4 | 0.3% | Mar 27, 2026 | A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /... |
| CVE-2026-4908 | CRITICAL | 9.8 | 0.4% | Mar 27, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ... |
| CVE-2026-4907 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted... |
| CVE-2026-4906 | HIGH | 8.8 | 2.6% | Mar 27, 2026 | A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof... |
| CVE-2026-33935 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att... |
| CVE-2026-33890 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att... |
| CVE-2026-33747 | CRITICAL | 9.8 | 0.5% | Mar 27, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P... |
| CVE-2026-33745 | HIGH | 7.4 | 0.3% | Mar 27, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP ... |
| CVE-2026-33744 | HIGH | 7.8 | 0.3% | Mar 27, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-33735 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas... |
| CVE-2026-33730 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2026-33729 | CRITICAL | 9.8 | 0.2% | Mar 27, 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2026-33728 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI ins... |
| CVE-2026-33726 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.... |
| CVE-2026-33725 | HIGH | 7.2 | 0.8% | Mar 27, 2026 | Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1... |
| CVE-2026-33721 | HIGH | 7.5 | 0.9% | Mar 27, 2026 | MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h... |
| CVE-2026-33718 | CRITICAL | 9.9 | 1.9% | Mar 27, 2026 | OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in ... |
| CVE-2026-33701 | CRITICAL | 9.8 | 0.9% | Mar 27, 2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I... |
| CVE-2026-33699 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack... |
| CVE-2026-33693 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in... |
| CVE-2026-4905 | HIGH | 8.8 | 0.6% | Mar 27, 2026 | A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsO... |
| CVE-2026-4904 | HIGH | 8.8 | 0.7% | Mar 27, 2026 | A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/... |
| CVE-2026-33945 | CRITICAL | 9.6 | 0.4% | Mar 27, 2026 | Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to system... |
| CVE-2026-33898 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now