2026 CVE Vulnerabilities
67,237 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3225 | MEDIUM | 4.3 | 0.3% | Mar 23, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answe... |
| CVE-2026-33168 | LOW | 2.3 | 0.5% | Mar 23, 2026 | Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1,... |
| CVE-2026-33167 | MEDIUM | 6.1 | 0.4% | Mar 23, 2026 | Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.... |
| CVE-2026-33046 | HIGH | 8.8 | 0.8% | Mar 23, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers... |
| CVE-2026-2412 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter... |
| CVE-2026-4681 | CRITICAL | 9.3 | 0.7% | Mar 23, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili... |
| CVE-2026-4612 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the fi... |
| CVE-2026-4611 | HIGH | 8.8 | 3.0% | Mar 23, 2026 | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the fu... |
| CVE-2026-33634 | HIGH | 8.8 | 60.4% | Mar 23, 2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy... |
| CVE-2026-32913 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom... |
| CVE-2026-32912 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32911 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32910 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32909 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32908 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32907 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32904 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32903 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32902 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32901 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32900 | — | — | — | Mar 23, 2026 | Rejected reason: This CVE ID has been rejected. |
| CVE-2026-32300 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32299 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32279 | MEDIUM | 6.8 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32278 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now