2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24516 | HIGH | 8.8 | 2.5% | Mar 23, 2026 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner compo... |
| CVE-2026-4592 | MEDIUM | 5.6 | 0.3% | Mar 23, 2026 | A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of t... |
| CVE-2026-4591 | MEDIUM | 4.7 | 2.1% | Mar 23, 2026 | A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/sourc... |
| CVE-2026-33493 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoi... |
| CVE-2026-33492 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function... |
| CVE-2026-33488 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L... |
| CVE-2026-32845 | HIGH | 8.4 | 0.1% | Mar 23, 2026 | cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating ... |
| CVE-2026-4590 | LOW | 3.1 | 0.1% | Mar 23, 2026 | A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /w... |
| CVE-2026-4404 | CRITICAL | 9.4 | 0.5% | Mar 23, 2026 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password ... |
| CVE-2026-33485 | HIGH | 7.5 | 0.5% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `p... |
| CVE-2026-33483 | HIGH | 7.5 | 0.6% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en... |
| CVE-2026-33482 | HIGH | 8.1 | 2.1% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi... |
| CVE-2026-33480 | HIGH | 8.6 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AV... |
| CVE-2026-33479 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.... |
| CVE-2026-33478 | CRITICAL | 10 | 13.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's... |
| CVE-2026-33354 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.ph... |
| CVE-2026-4647 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files... |
| CVE-2026-4645 | — | — | — | Mar 23, 2026 | Rejected reason: Duplicate of CVE-2026-32287 |
| CVE-2026-4589 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file ... |
| CVE-2026-3635 | MEDIUM | 6.1 | 0.1% | Mar 23, 2026 | Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1'... |
| CVE-2026-33352 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exis... |
| CVE-2026-33351 | CRITICAL | 9.1 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability ... |
| CVE-2026-33297 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz... |
| CVE-2026-4588 | LOW | 3.7 | 0.3% | Mar 23, 2026 | A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/... |
| CVE-2026-4587 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now