2026 CVE Vulnerabilities
67,331 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32829 | HIGH | 7.5 | 0.6% | Mar 20, 2026 | lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, deco... |
| CVE-2026-32828 | MEDIUM | 4.9 | 0.3% | Mar 20, 2026 | Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7... |
| CVE-2026-32771 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met... |
| CVE-2026-32769 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-wr... |
| CVE-2026-32767 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability... |
| CVE-2026-33289 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-33288 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-32985 | CRITICAL | 9.8 | 1.5% | Mar 20, 2026 | Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te... |
| CVE-2026-32766 | MEDIUM | 5.3 | 0.2% | Mar 20, 2026 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX e... |
| CVE-2026-32765 | — | — | — | Mar 20, 2026 | Rejected reason: This repository is no longer public. |
| CVE-2026-32764 | — | — | — | Mar 20, 2026 | Rejected reason: This repository is no longer public. |
| CVE-2026-32763 | HIGH | 8.2 | 0.4% | Mar 20, 2026 | Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerabili... |
| CVE-2026-32761 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-32760 | CRITICAL | 9.8 | 0.7% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-32759 | HIGH | 8.1 | 1.9% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-32758 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-32757 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POS... |
| CVE-2026-32756 | HIGH | 8.8 | 1.0% | Mar 20, 2026 | Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload... |
| CVE-2026-32697 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29189 | HIGH | 8.1 | 0.3% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29109 | HIGH | 7.2 | 0.5% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to... |
| CVE-2026-29108 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-22737 | MEDIUM | 5.9 | 0.4% | Mar 20, 2026 | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c... |
| CVE-2026-22735 | LOW | 2.6 | 0.1% | Mar 20, 2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue ... |
| CVE-2026-22733 | HIGH | 8.1 | 0.4% | Mar 20, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now