2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2378 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content bein... |
| CVE-2026-23536 | HIGH | 7.5 | 0.6% | Mar 20, 2026 | A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r... |
| CVE-2026-33179 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer ... |
| CVE-2026-33165 | MEDIUM | 5 | 0.2% | Mar 20, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream ca... |
| CVE-2026-33164 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u... |
| CVE-2026-33156 | HIGH | 7.8 | 0.2% | Mar 20, 2026 | ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading ... |
| CVE-2026-33155 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6... |
| CVE-2026-33154 | HIGH | 8.1 | 0.5% | Mar 20, 2026 | dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T... |
| CVE-2026-33151 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.... |
| CVE-2026-33150 | HIGH | 7.8 | 0.3% | Mar 20, 2026 | libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-fre... |
| CVE-2026-33147 | HIGH | 7.8 | 0.2% | Mar 20, 2026 | GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions ... |
| CVE-2026-33144 | HIGH | 7.8 | 0.2% | Mar 20, 2026 | GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability... |
| CVE-2026-33143 | HIGH | 7.5 | 0.2% | Mar 20, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook... |
| CVE-2026-33142 | HIGH | 8.1 | 0.3% | Mar 20, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-3230... |
| CVE-2026-4505 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh... |
| CVE-2026-4504 | HIGH | 7.3 | 0.3% | Mar 20, 2026 | A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/ed... |
| CVE-2026-4500 | MEDIUM | 6.3 | 0.4% | Mar 20, 2026 | A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the fil... |
| CVE-2026-4499 | CRITICAL | 9.8 | 3.2% | Mar 20, 2026 | A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex... |
| CVE-2026-4438 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the... |
| CVE-2026-4437 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the... |
| CVE-2026-33140 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS... |
| CVE-2026-33139 | HIGH | 7.8 | 0.2% | Mar 20, 2026 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS... |
| CVE-2026-33126 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, ... |
| CVE-2026-4497 | CRITICAL | 9.8 | 1.9% | Mar 20, 2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad... |
| CVE-2026-4496 | MEDIUM | 5.3 | 0.7% | Mar 20, 2026 | A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now