2026 CVE Vulnerabilities
67,276 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33055 | HIGH | 8.1 | 0.4% | Mar 20, 2026 | tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips th... |
| CVE-2026-33054 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Pat... |
| CVE-2026-33053 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_ap... |
| CVE-2026-4473 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown proce... |
| CVE-2026-33051 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu... |
| CVE-2026-33043 | HIGH | 8.1 | 0.3% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the cur... |
| CVE-2026-33041 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the appl... |
| CVE-2026-33040 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, th... |
| CVE-2026-33039 | HIGH | 8.6 | 0.5% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint valida... |
| CVE-2026-33038 | HIGH | 8.1 | 0.5% | Mar 20, 2026 | WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application take... |
| CVE-2026-33037 | HIGH | 8.1 | 0.7% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-c... |
| CVE-2026-33036 | HIGH | 7.5 | 0.6% | Mar 20, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-be... |
| CVE-2026-32768 | CRITICAL | 9.9 | 0.3% | Mar 20, 2026 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, ... |
| CVE-2026-4472 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability a... |
| CVE-2026-4471 | CRITICAL | 9.8 | 0.4% | Mar 20, 2026 | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ... |
| CVE-2026-4470 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is s... |
| CVE-2026-4469 | CRITICAL | 9.8 | 0.3% | Mar 20, 2026 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability i... |
| CVE-2026-33035 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that al... |
| CVE-2026-33025 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() ... |
| CVE-2026-33024 | CRITICAL | 9.1 | 0.4% | Mar 20, 2026 | AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) ... |
| CVE-2026-33017 | CRITICAL | 9.8 | 98.4% | Mar 20, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api... |
| CVE-2026-33013 | HIGH | 7.5 | 0.6% | Mar 20, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-33012 | HIGH | 7.5 | 0.6% | Mar 20, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-33011 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS appl... |
| CVE-2026-32954 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now