2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33010 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP ser... |
| CVE-2026-32710 | CRITICAL | 9.9 | 0.9% | Mar 20, 2026 | MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 befo... |
| CVE-2026-32318 | MEDIUM | 5.9 | 0.1% | Mar 20, 2026 | Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.... |
| CVE-2026-32317 | MEDIUM | 5.9 | 0.1% | Mar 20, 2026 | Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio... |
| CVE-2026-32310 | MEDIUM | 5.3 | 0.2% | Mar 20, 2026 | Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault confi... |
| CVE-2026-32309 | HIGH | 7.5 | 0.2% | Mar 20, 2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow expli... |
| CVE-2026-4495 | LOW | 3.5 | 0.3% | Mar 20, 2026 | A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/... |
| CVE-2026-4494 | LOW | 3.5 | 0.3% | Mar 20, 2026 | A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/... |
| CVE-2026-4493 | HIGH | 8.8 | 0.6% | Mar 20, 2026 | A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file... |
| CVE-2026-4492 | HIGH | 8.8 | 0.6% | Mar 20, 2026 | A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file... |
| CVE-2026-32844 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.... |
| CVE-2026-32303 | MEDIUM | 5.9 | 0.1% | Mar 20, 2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit... |
| CVE-2026-31836 | HIGH | 8.1 | 0.3% | Mar 20, 2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and... |
| CVE-2026-30580 | MEDIUM | 4.3 | 0.6% | Mar 20, 2026 | File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" func... |
| CVE-2026-30579 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" function... |
| CVE-2026-30578 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of th... |
| CVE-2026-4491 | HIGH | 8.8 | 0.5% | Mar 20, 2026 | A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /gofo... |
| CVE-2026-4490 | HIGH | 8.8 | 0.6% | Mar 20, 2026 | A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/ope... |
| CVE-2026-29828 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field proj... |
| CVE-2026-22902 | MEDIUM | 6.7 | 0.5% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac... |
| CVE-2026-22901 | CRITICAL | 9.8 | 0.9% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, th... |
| CVE-2026-22900 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exp... |
| CVE-2026-22898 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers c... |
| CVE-2026-22897 | CRITICAL | 9.8 | 1.1% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vul... |
| CVE-2026-22895 | MEDIUM | 4.8 | 0.2% | Mar 20, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an admi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now