2026 CVE Vulnerabilities
67,228 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33307 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client cer... |
| CVE-2026-4680 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-4679 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds... |
| CVE-2026-4678 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-4677 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform a... |
| CVE-2026-4676 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-4675 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bo... |
| CVE-2026-4674 | HIGH | 8.8 | 0.5% | Mar 24, 2026 | Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds me... |
| CVE-2026-4673 | HIGH | 8.8 | 0.5% | Mar 24, 2026 | Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of... |
| CVE-2026-4617 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element... |
| CVE-2026-4616 | LOW | 2.4 | 0.3% | Mar 24, 2026 | A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /c... |
| CVE-2026-33320 | MEDIUM | 6.2 | 0.2% | Mar 24, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version ... |
| CVE-2026-33306 | HIGH | 7.5 | 0.2% | Mar 24, 2026 | bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer o... |
| CVE-2026-33298 | HIGH | 7.8 | 0.5% | Mar 24, 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml... |
| CVE-2026-33290 | MEDIUM | 4.3 | 0.2% | Mar 24, 2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment al... |
| CVE-2026-22739 | HIGH | 8.6 | 1.2% | Mar 24, 2026 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Ser... |
| CVE-2026-4615 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the... |
| CVE-2026-4614 | MEDIUM | 6.3 | 0.2% | Mar 24, 2026 | A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc... |
| CVE-2026-4613 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /pr... |
| CVE-2026-4056 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2026-4021 | HIGH | 8.1 | 0.4% | Mar 24, 2026 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in ... |
| CVE-2026-4001 | CRITICAL | 9.8 | 0.7% | Mar 24, 2026 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up... |
| CVE-2026-3533 | HIGH | 8.8 | 0.7% | Mar 24, 2026 | The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop... |
| CVE-2026-33286 | CRITICAL | 9.1 | 0.6% | Mar 24, 2026 | Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior t... |
| CVE-2026-33283 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now