2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33688 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o... |
| CVE-2026-33685 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.p... |
| CVE-2026-33683 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations f... |
| CVE-2026-33681 | HIGH | 7.2 | 0.5% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript... |
| CVE-2026-33651 | HIGH | 8.8 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas... |
| CVE-2026-33650 | HIGH | 7.6 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p... |
| CVE-2026-33649 | HIGH | 8.8 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermissio... |
| CVE-2026-33648 | HIGH | 8.8 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a... |
| CVE-2026-33647 | HIGH | 8.8 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` metho... |
| CVE-2026-33513 | HIGH | 7.5 | 0.7% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`AP... |
| CVE-2026-33512 | HIGH | 7.5 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr... |
| CVE-2026-26209 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions ... |
| CVE-2026-25075 | HIGH | 8.7 | 1.0% | Mar 23, 2026 | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo... |
| CVE-2026-0898 | CRITICAL | 9 | 0.3% | Mar 23, 2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom... |
| CVE-2026-4594 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy ... |
| CVE-2026-4593 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f... |
| CVE-2026-33507 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` ... |
| CVE-2026-33502 | HIGH | 8.2 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side reque... |
| CVE-2026-33501 | MEDIUM | 5.3 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/Vie... |
| CVE-2026-33500 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcq... |
| CVE-2026-33499 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `vi... |
| CVE-2026-30007 | MEDIUM | 6.2 | 0.2% | Mar 23, 2026 | XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file |
| CVE-2026-30006 | MEDIUM | 6.2 | 0.2% | Mar 23, 2026 | XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file. |
| CVE-2026-26829 | HIGH | 7.5 | 0.9% | Mar 23, 2026 | A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows atta... |
| CVE-2026-26828 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now