2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4489 | HIGH | 8.8 | 0.5% | Mar 20, 2026 | A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wif... |
| CVE-2026-4488 | HIGH | 8.8 | 0.5% | Mar 20, 2026 | A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the fil... |
| CVE-2026-32989 | HIGH | 8.8 | 0.2% | Mar 20, 2026 | Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authent... |
| CVE-2026-32986 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject... |
| CVE-2026-4519 | LOW | 3.3 | 0.3% | Mar 20, 2026 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer... |
| CVE-2026-4487 | HIGH | 8.8 | 0.5% | Mar 20, 2026 | A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /gof... |
| CVE-2026-33312 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, t... |
| CVE-2026-29794 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau... |
| CVE-2026-22172 | CRITICAL | 9.9 | 0.5% | Mar 20, 2026 | OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that al... |
| CVE-2026-4486 | HIGH | 8.8 | 0.6% | Mar 20, 2026 | A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/form... |
| CVE-2026-4485 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio... |
| CVE-2026-33372 | MEDIUM | 5.4 | 0.1% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability e... |
| CVE-2026-33371 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i... |
| CVE-2026-33370 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability e... |
| CVE-2026-33369 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a F... |
| CVE-2026-33368 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Clas... |
| CVE-2026-31382 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s... |
| CVE-2026-31381 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb... |
| CVE-2026-4434 | HIGH | 8.1 | 0.1% | Mar 20, 2026 | Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-... |
| CVE-2026-33136 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33135 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33134 | HIGH | 8.8 | 0.3% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vuln... |
| CVE-2026-33133 | HIGH | 7.2 | 0.4% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL... |
| CVE-2026-33132 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t... |
| CVE-2026-33131 | CRITICAL | 9.1 | 0.4% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now