2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33203 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una... |
| CVE-2026-33194 | MEDIUM | 6.8 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut... |
| CVE-2026-33186 | CRITICAL | 9.1 | 1.6% | Mar 20, 2026 | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ... |
| CVE-2026-33180 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-32810 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c... |
| CVE-2026-32733 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive ... |
| CVE-2026-32663 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-31926 | MEDIUM | 6.9 | 0.3% | Mar 20, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-31904 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-31903 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-2598 | — | — | — | Mar 20, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-29796 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-28204 | MEDIUM | 6.9 | 0.3% | Mar 20, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-27649 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-25192 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-22163 | HIGH | 7.8 | 0.1% | Mar 20, 2026 | Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupporte... |
| CVE-2026-21732 | CRITICAL | 9.6 | 0.3% | Mar 20, 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-... |
| CVE-2026-4507 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the ... |
| CVE-2026-4506 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core... |
| CVE-2026-3584 | CRITICAL | 9.8 | 7.2% | Mar 20, 2026 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v... |
| CVE-2026-33177 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileg... |
| CVE-2026-33172 | HIGH | 8.7 | 0.3% | Mar 20, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS... |
| CVE-2026-33171 | MEDIUM | 4.3 | 0.3% | Mar 20, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticate... |
| CVE-2026-33166 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator p... |
| CVE-2026-32887 | HIGH | 7.4 | 0.3% | Mar 20, 2026 | Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applicati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now