2026 CVE Vulnerabilities
67,227 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33474 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0... |
| CVE-2026-33473 | MEDIUM | 5.7 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any... |
| CVE-2026-33336 | HIGH | 8.8 | 1.1% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-33335 | HIGH | 8 | 0.2% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-33334 | CRITICAL | 9.6 | 0.4% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-29840 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app... |
| CVE-2026-29839 | HIGH | 8.8 | 0.1% | Mar 24, 2026 | DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. |
| CVE-2026-4775 | HIGH | 7.8 | 0.4% | Mar 24, 2026 | A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the ... |
| CVE-2026-33554 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Manag... |
| CVE-2026-33316 | HIGH | 8.1 | 0.4% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res... |
| CVE-2026-33315 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login... |
| CVE-2026-33313 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read a... |
| CVE-2026-32647 | HIGH | 8.5 | 0.9% | Mar 24, 2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker t... |
| CVE-2026-30662 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method... |
| CVE-2026-30661 | MEDIUM | 6.1 | 0.2% | Mar 24, 2026 | iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within th... |
| CVE-2026-30655 | MEDIUM | 6.5 | 0.5% | Mar 24, 2026 | SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote atta... |
| CVE-2026-30653 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuth... |
| CVE-2026-28755 | MEDIUM | 5.4 | 0.1% | Mar 24, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o... |
| CVE-2026-28753 | MEDIUM | 6.3 | 0.3% | Mar 24, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of... |
| CVE-2026-27784 | HIGH | 8.5 | 1.0% | Mar 24, 2026 | The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow ... |
| CVE-2026-27654 | HIGH | 8.8 | 21.6% | Mar 24, 2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to ... |
| CVE-2026-27651 | HIGH | 8.7 | 0.9% | Mar 24, 2026 | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause ... |
| CVE-2026-33497 | HIGH | 7.5 | 8.0% | Mar 24, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_p... |
| CVE-2026-33484 | HIGH | 7.5 | 5.8% | Mar 24, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/ap... |
| CVE-2026-33418 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | DiceBear is an avatar library for designers and developers. Prior to version 9.4.2, the `ensureSize()` function in `@dic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now