2026 CVE Vulnerabilities
67,228 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4639 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated rem... |
| CVE-2026-4632 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of ... |
| CVE-2026-4627 | HIGH | 8.6 | 2.0% | Mar 24, 2026 | A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_tim... |
| CVE-2026-4283 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, ... |
| CVE-2026-3260 | — | — | 0.4% | Mar 24, 2026 | Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (includi... |
| CVE-2026-3138 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing ... |
| CVE-2026-4744 | CRITICAL | 9.3 | 0.1% | Mar 24, 2026 | Out-of-bounds Read vulnerability in rizonesoft Notepad3 (scintilla/oniguruma/src modules). This vulnerability is associ... |
| CVE-2026-4743 | MEDIUM | 5.2 | 0.1% | Mar 24, 2026 | NULL Pointer Dereference vulnerability in taurusxin ncmdump (src/utils modules). This vulnerability is associated with... |
| CVE-2026-4742 | LOW | 2.9 | 0.2% | Mar 24, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (lite... |
| CVE-2026-4741 | HIGH | 8.6 | 0.4% | Mar 24, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app... |
| CVE-2026-4739 | CRITICAL | 9.4 | 0.3% | Mar 24, 2026 | Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (Modules/ThirdParty/Expat/src/expat modul... |
| CVE-2026-4738 | CRITICAL | 9.4 | 0.3% | Mar 24, 2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/... |
| CVE-2026-4737 | HIGH | 7.3 | 0.1% | Mar 24, 2026 | Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerabili... |
| CVE-2026-4736 | HIGH | 7.3 | 0.1% | Mar 24, 2026 | Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfi... |
| CVE-2026-4735 | HIGH | 8.7 | 0.3% | Mar 24, 2026 | Deserialization of Untrusted Data vulnerability in DTStack chunjun (chunjun-core/src/main/java/com/dtstack/chunjun/util... |
| CVE-2026-4734 | CRITICAL | 9.4 | 0.3% | Mar 24, 2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt... |
| CVE-2026-4733 | MEDIUM | 5.3 | 0.2% | Mar 24, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect... |
| CVE-2026-4732 | HIGH | 8.4 | 0.1% | Mar 24, 2026 | Out-of-bounds Read vulnerability in tildearrow furnace (extern/libsndfile-modified/src modules). This vulnerability is ... |
| CVE-2026-4731 | HIGH | 8.5 | 0.1% | Mar 24, 2026 | Integer Overflow or Wraparound vulnerability in artraweditor ART (rtengine modules). This vulnerability is associated ... |
| CVE-2026-4626 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the fi... |
| CVE-2026-4625 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A flaw has been found in SourceCodester Online Admission System 1.0. This affects an unknown function of the file /progr... |
| CVE-2026-4624 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A vulnerability was detected in SourceCodester Online Library Management System 1.0. The impacted element is an unknown ... |
| CVE-2026-4623 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c... |
| CVE-2026-33308 | MEDIUM | 5.9 | 0.2% | Mar 24, 2026 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verifi... |
| CVE-2026-3079 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now