2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32595 | LOW | 3.7 | 0.4% | Mar 20, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea... |
| CVE-2026-32305 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea... |
| CVE-2026-25792 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path... |
| CVE-2026-33130 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p... |
| CVE-2026-33129 | MEDIUM | 5.9 | 0.3% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i... |
| CVE-2026-33128 | CRITICAL | 10 | 0.5% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream i... |
| CVE-2026-33125 | HIGH | 8.1 | 0.2% | Mar 20, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and be... |
| CVE-2026-33124 | HIGH | 8.8 | 0.2% | Mar 20, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-... |
| CVE-2026-33123 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious ... |
| CVE-2026-33081 | LOW | 3.7 | 0.3% | Mar 20, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below... |
| CVE-2026-22324 | HIGH | 8.1 | 0.5% | Mar 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-0677 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injectio... |
| CVE-2026-3550 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. ... |
| CVE-2026-33192 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.... |
| CVE-2026-33080 | MEDIUM | 5.4 | 0.3% | Mar 20, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and ... |
| CVE-2026-33075 | HIGH | 8.8 | 0.3% | Mar 20, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln... |
| CVE-2026-33072 | HIGH | 7.5 | 0.2% | Mar 20, 2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption k... |
| CVE-2026-33071 | HIGH | 8.8 | 0.6% | Mar 20, 2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accep... |
| CVE-2026-33070 | MEDIUM | 4.8 | 0.4% | Mar 20, 2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnera... |
| CVE-2026-33069 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading ... |
| CVE-2026-33068 | HIGH | 8.8 | 0.3% | Mar 20, 2026 | Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, includ... |
| CVE-2026-33067 | CRITICAL | 9 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, ... |
| CVE-2026-33066 | CRITICAL | 9 | 0.6% | Mar 20, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lu... |
| CVE-2026-32701 | HIGH | 7.5 | 0.4% | Mar 20, 2026 | Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form... |
| CVE-2026-2432 | MEDIUM | 4.4 | 0.2% | Mar 20, 2026 | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now