2026 CVE Vulnerabilities
67,127 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33697 | MEDIUM | 6.3 | 0.1% | Mar 27, 2026 | Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner... |
| CVE-2026-29071 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-29070 | HIGH | 8.1 | 0.3% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-28788 | HIGH | 7.1 | 2.9% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-28786 | MEDIUM | 4.3 | 0.4% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-27893 | HIGH | 8.8 | 1.4% | Mar 27, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio... |
| CVE-2026-4903 | HIGH | 8.8 | 5.5% | Mar 26, 2026 | A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /gofo... |
| CVE-2026-4902 | HIGH | 8.8 | 0.6% | Mar 26, 2026 | A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addr... |
| CVE-2026-34352 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or ... |
| CVE-2026-33897 | CRITICAL | 9.9 | 0.5% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to... |
| CVE-2026-33743 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac... |
| CVE-2026-33711 | HIGH | 7.8 | 0.4% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API reli... |
| CVE-2026-33542 | MEDIUM | 4.8 | 0.2% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing... |
| CVE-2026-4900 | MEDIUM | 5.5 | 0.4% | Mar 26, 2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2026-4899 | LOW | 2.4 | 0.3% | Mar 26, 2026 | A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unk... |
| CVE-2026-4898 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un... |
| CVE-2026-4346 | MEDIUM | 6.8 | 0.1% | Mar 26, 2026 | The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of... |
| CVE-2026-3650 | HIGH | 8.7 | 0.4% | Mar 26, 2026 | A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-... |
| CVE-2026-33687 | HIGH | 8.8 | 0.5% | Mar 26, 2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability... |
| CVE-2026-33686 | HIGH | 8.8 | 0.5% | Mar 26, 2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal v... |
| CVE-2026-33682 | MEDIUM | 4.8 | 0.3% | Mar 26, 2026 | Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.... |
| CVE-2026-33674 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation... |
| CVE-2026-33673 | MEDIUM | 5.4 | 0.3% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros... |
| CVE-2026-33672 | MEDIUM | 5.3 | 0.4% | Mar 26, 2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj... |
| CVE-2026-33671 | HIGH | 7.5 | 0.4% | Mar 26, 2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now