2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3216 | MEDIUM | 5 | 0.3% | Mar 25, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue a... |
| CVE-2026-3215 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora a... |
| CVE-2026-3214 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.Thi... |
| CVE-2026-3213 | MEDIUM | 4.7 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b... |
| CVE-2026-3212 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo... |
| CVE-2026-3211 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.T... |
| CVE-2026-3210 | MEDIUM | 5.3 | 0.2% | Mar 25, 2026 | Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icon... |
| CVE-2026-2349 | MEDIUM | 6.1 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons al... |
| CVE-2026-2348 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit ... |
| CVE-2026-26833 | CRITICAL | 9.8 | 2.3% | Mar 25, 2026 | thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun... |
| CVE-2026-26832 | CRITICAL | 9.8 | 1.7% | Mar 25, 2026 | node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, t... |
| CVE-2026-26831 | CRITICAL | 9.8 | 2.4% | Mar 25, 2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr... |
| CVE-2026-24750 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attac... |
| CVE-2026-20125 | HIGH | 7.7 | 0.3% | Mar 25, 2026 | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut... |
| CVE-2026-20115 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confide... |
| CVE-2026-20114 | MEDIUM | 5.4 | 0.3% | Mar 25, 2026 | A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, ... |
| CVE-2026-20113 | MEDIUM | 5.3 | 0.3% | Mar 25, 2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software... |
| CVE-2026-20112 | MEDIUM | 4.8 | 0.2% | Mar 25, 2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software... |
| CVE-2026-20110 | MEDIUM | 6.5 | 0.1% | Mar 25, 2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of se... |
| CVE-2026-20108 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem... |
| CVE-2026-20104 | MEDIUM | 6.1 | — | Mar 25, 2026 | A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93... |
| CVE-2026-20086 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE... |
| CVE-2026-20084 | HIGH | 8.6 | — | Mar 25, 2026 | A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
| CVE-2026-20083 | MEDIUM | 6.5 | 0.1% | Mar 25, 2026 | A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, ... |
| CVE-2026-20012 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cis... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now