2026 CVE Vulnerabilities
67,358 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32119 | MEDIUM | 4.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-25928 | MEDIUM | 6.5 | 0.5% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-25744 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-3503 | MEDIUM | 5.2 | 0.2% | Mar 19, 2026 | Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi... |
| CVE-2026-25667 | HIGH | 7.5 | 3.0% | Mar 19, 2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex... |
| CVE-2026-3548 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over... |
| CVE-2026-30694 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone... |
| CVE-2026-2646 | HIGH | 8.1 | 0.1% | Mar 19, 2026 | A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ... |
| CVE-2026-2645 | HIGH | 7.5 | 0.1% | Mar 19, 2026 | In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ... |
| CVE-2026-26940 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De... |
| CVE-2026-26939 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp... |
| CVE-2026-26933 | MEDIUM | 5.7 | 0.2% | Mar 19, 2026 | Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser... |
| CVE-2026-30403 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ... |
| CVE-2026-26931 | MEDIUM | 5.7 | 0.2% | Mar 19, 2026 | Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead... |
| CVE-2026-1005 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio... |
| CVE-2026-0819 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign... |
| CVE-2026-3029 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver... |
| CVE-2026-32869 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w... |
| CVE-2026-32868 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ... |
| CVE-2026-32867 | CRITICAL | 9.8 | 0.2% | Mar 19, 2026 | OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ... |
| CVE-2026-32866 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us... |
| CVE-2026-32865 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque... |
| CVE-2026-30404 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne... |
| CVE-2026-4427 | — | — | — | Mar 19, 2026 | Rejected reason: Duplicate of CVE-2026-32286 |
| CVE-2026-4426 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now