2026 CVE Vulnerabilities
67,358 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33299 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-32749 | CRITICAL | 9.1 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i... |
| CVE-2026-32747 | MEDIUM | 4.9 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file... |
| CVE-2026-32622 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S... |
| CVE-2026-32191 | CRITICAL | 9.8 | 0.6% | Mar 19, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo... |
| CVE-2026-32169 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-30924 | CRITICAL | 9.6 | 0.3% | Mar 19, 2026 | qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r... |
| CVE-2026-30836 | CRITICAL | 10 | 0.3% | Mar 19, 2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ... |
| CVE-2026-27953 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the... |
| CVE-2026-27740 | MEDIUM | 6.1 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros... |
| CVE-2026-27570 | MEDIUM | 6.1 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox... |
| CVE-2026-27491 | MEDIUM | 4.3 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe... |
| CVE-2026-27454 | MEDIUM | 5.3 | 0.4% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting... |
| CVE-2026-27166 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie... |
| CVE-2026-26139 | HIGH | 8.6 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-26138 | CRITICAL | 10 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-26137 | CRITICAL | 9.9 | 0.5% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw... |
| CVE-2026-26136 | HIGH | 7.5 | 0.7% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-26120 | HIGH | 7.5 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network... |
| CVE-2026-24299 | MEDIUM | 5.3 | 0.6% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-23659 | HIGH | 7.5 | 0.8% | Mar 19, 2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc... |
| CVE-2026-23658 | CRITICAL | 9.8 | 0.8% | Mar 19, 2026 | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ... |
| CVE-2026-3580 | MEDIUM | 4.7 | 0.1% | Mar 19, 2026 | In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by... |
| CVE-2026-3579 | MEDIUM | 5.9 | 0.3% | Mar 19, 2026 | wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The... |
| CVE-2026-32238 | CRITICAL | 9.1 | 1.9% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now