2026 CVE Vulnerabilities
67,353 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30871 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md... |
| CVE-2026-29072 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who ... |
| CVE-2026-28282 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu... |
| CVE-2026-27936 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restrict... |
| CVE-2026-27935 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln... |
| CVE-2026-27934 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack... |
| CVE-2026-4428 | CRITICAL | 9.1 | 0.3% | Mar 19, 2026 | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rej... |
| CVE-2026-4395 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote at... |
| CVE-2026-3849 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E... |
| CVE-2026-3549 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf... |
| CVE-2026-3547 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re... |
| CVE-2026-3230 | LOW | 2.7 | 0.2% | Mar 19, 2026 | Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a c... |
| CVE-2026-3229 | MEDIUM | 5.5 | 0.1% | Mar 19, 2026 | An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when ... |
| CVE-2026-33346 | HIGH | 8.7 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33321 | HIGH | 7.6 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33305 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33304 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33303 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2026-33302 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33301 | HIGH | 8.1 | 0.4% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33299 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-32749 | CRITICAL | 9.1 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i... |
| CVE-2026-32747 | MEDIUM | 4.9 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file... |
| CVE-2026-32622 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S... |
| CVE-2026-32191 | CRITICAL | 9.8 | 0.6% | Mar 19, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now