2026 CVE Vulnerabilities
67,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25086 | HIGH | 7.7 | 0.2% | Mar 21, 2026 | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra... |
| CVE-2026-24060 | CRITICAL | 9.1 | 0.2% | Mar 21, 2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted,... |
| CVE-2026-4508 | HIGH | 7.3 | 0.3% | Mar 20, 2026 | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file ... |
| CVE-2026-3864 | MEDIUM | 6.5 | 0.5% | Mar 20, 2026 | A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was... |
| CVE-2026-33476 | HIGH | 7.5 | 3.3% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f... |
| CVE-2026-33423 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can ... |
| CVE-2026-33422 | MEDIUM | 4.3 | 0.3% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_a... |
| CVE-2026-33411 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a pote... |
| CVE-2026-33291 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators... |
| CVE-2026-33251 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authori... |
| CVE-2026-33243 | HIGH | 8.2 | 0.1% | Mar 20, 2026 | barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t... |
| CVE-2026-33236 | HIGH | 8.1 | 0.5% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33231 | HIGH | 7.5 | 0.9% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33230 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33228 | CRITICAL | 9.8 | 0.8% | Mar 20, 2026 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s... |
| CVE-2026-33226 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr... |
| CVE-2026-33221 | MEDIUM | 5.3 | 0.2% | Mar 20, 2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha... |
| CVE-2026-33210 | CRITICAL | 9.1 | 0.8% | Mar 20, 2026 | Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo... |
| CVE-2026-33209 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script... |
| CVE-2026-33204 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per... |
| CVE-2026-33203 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una... |
| CVE-2026-33194 | MEDIUM | 6.8 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut... |
| CVE-2026-33186 | CRITICAL | 9.1 | 1.6% | Mar 20, 2026 | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ... |
| CVE-2026-33180 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-32810 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now