2026 CVE Vulnerabilities
67,248 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33297 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz... |
| CVE-2026-4588 | LOW | 3.7 | 0.3% | Mar 23, 2026 | A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/... |
| CVE-2026-4587 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli... |
| CVE-2026-4586 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-serve... |
| CVE-2026-31851 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec... |
| CVE-2026-31850 | MEDIUM | 4.9 | 0.2% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative ... |
| CVE-2026-31849 | MEDIUM | 6.5 | 0.1% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing e... |
| CVE-2026-31848 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which conta... |
| CVE-2026-31847 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0... |
| CVE-2026-1958 | HIGH | 8.7 | 0.3% | Mar 23, 2026 | Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several i... |
| CVE-2026-4585 | CRITICAL | 9.8 | 3.3% | Mar 23, 2026 | A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects u... |
| CVE-2026-4584 | LOW | 3.1 | 0.2% | Mar 23, 2026 | A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Car... |
| CVE-2026-32969 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s a... |
| CVE-2026-32968 | CRITICAL | 9.8 | 0.5% | Mar 23, 2026 | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exp... |
| CVE-2026-31846 | HIGH | 7.1 | 0.3% | Mar 23, 2026 | Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 a... |
| CVE-2026-4633 | LOW | 3.7 | 0.3% | Mar 23, 2026 | A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login ... |
| CVE-2026-4583 | MEDIUM | 5 | 0.3% | Mar 23, 2026 | A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun... |
| CVE-2026-28809 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local fi... |
| CVE-2026-4582 | MEDIUM | 5 | 0.3% | Mar 23, 2026 | A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili... |
| CVE-2026-4581 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /... |
| CVE-2026-4628 | MEDIUM | 4.3 | 0.2% | Mar 23, 2026 | A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_... |
| CVE-2026-4580 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ... |
| CVE-2026-4579 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ... |
| CVE-2026-4578 | LOW | 2.4 | 0.3% | Mar 23, 2026 | A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of... |
| CVE-2026-3587 | CRITICAL | 10 | 0.7% | Mar 23, 2026 | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now