2026 CVE Vulnerabilities
67,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32948 | HIGH | 7.8 | 0.3% | Mar 24, 2026 | sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Proce... |
| CVE-2026-22559 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the ac... |
| CVE-2026-21783 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provid... |
| CVE-2026-33769 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path... |
| CVE-2026-33768 | CRITICAL | 9.1 | 0.3% | Mar 24, 2026 | Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head... |
| CVE-2026-33627 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33624 | LOW | 2.7 | 0.2% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33539 | HIGH | 7.2 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33538 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33527 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33508 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33498 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33429 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33421 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33417 | HIGH | 7.1 | 0.3% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in ... |
| CVE-2026-33409 | CRITICAL | 9.1 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33323 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30932 | HIGH | 8.8 | 0.5% | Mar 24, 2026 | Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessi... |
| CVE-2026-2417 | CRITICAL | 9.3 | 0.6% | Mar 24, 2026 | A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version ... |
| CVE-2026-29772 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque... |
| CVE-2026-23924 | MEDIUM | 4.9 | 0.3% | Mar 24, 2026 | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t... |
| CVE-2026-23923 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The... |
| CVE-2026-23921 | HIGH | 8.8 | 2.9% | Mar 24, 2026 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS... |
| CVE-2026-23920 | HIGH | 8.8 | 0.2% | Mar 24, 2026 | Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult... |
| CVE-2026-23919 | MEDIUM | 6 | 0.2% | Mar 24, 2026 | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now