2026 CVE Vulnerabilities
67,237 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4615 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the... |
| CVE-2026-4614 | MEDIUM | 6.3 | 0.2% | Mar 24, 2026 | A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc... |
| CVE-2026-4613 | HIGH | 7.3 | 0.3% | Mar 24, 2026 | A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /pr... |
| CVE-2026-4056 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2026-4021 | HIGH | 8.1 | 0.4% | Mar 24, 2026 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in ... |
| CVE-2026-4001 | CRITICAL | 9.8 | 0.7% | Mar 24, 2026 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up... |
| CVE-2026-3533 | HIGH | 8.8 | 0.7% | Mar 24, 2026 | The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop... |
| CVE-2026-33286 | CRITICAL | 9.1 | 0.6% | Mar 24, 2026 | Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior t... |
| CVE-2026-33283 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra... |
| CVE-2026-33282 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP Loc... |
| CVE-2026-33281 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with i... |
| CVE-2026-33252 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted... |
| CVE-2026-33250 | HIGH | 7.5 | 0.8% | Mar 24, 2026 | Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack o... |
| CVE-2026-33242 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerabil... |
| CVE-2026-33241 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method ... |
| CVE-2026-33211 | CRITICAL | 9.6 | 0.6% | Mar 24, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-33202 | CRITICAL | 9.1 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33195 | CRITICAL | 9.8 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33176 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v... |
| CVE-2026-33174 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33173 | MEDIUM | 5.3 | 0.4% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33170 | MEDIUM | 6.1 | 0.3% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v... |
| CVE-2026-33169 | MEDIUM | 5.3 | 0.5% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD... |
| CVE-2026-4306 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, ... |
| CVE-2026-4066 | MEDIUM | 4.3 | 0.3% | Mar 23, 2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now