2026 CVE Vulnerabilities
67,363 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32866 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us... |
| CVE-2026-32865 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque... |
| CVE-2026-30404 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne... |
| CVE-2026-4427 | — | — | — | Mar 19, 2026 | Rejected reason: Duplicate of CVE-2026-32286 |
| CVE-2026-4426 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ... |
| CVE-2026-4424 | HIGH | 7.5 | — | Mar 19, 2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du... |
| CVE-2026-32843 | MEDIUM | 5.1 | 0.5% | Mar 19, 2026 | Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting... |
| CVE-2026-30711 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.... |
| CVE-2026-30402 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi... |
| CVE-2026-2369 | CRITICAL | 9.1 | 0.4% | Mar 19, 2026 | A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour... |
| CVE-2026-27043 | HIGH | 7.2 | 0.4% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue... |
| CVE-2026-22558 | HIGH | 7.7 | 0.5% | Mar 19, 2026 | An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut... |
| CVE-2026-22557 | CRITICAL | 10 | 15.6% | Mar 19, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App... |
| CVE-2026-3658 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL... |
| CVE-2026-3511 | HIGH | 8.6 | 0.3% | Mar 19, 2026 | Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow... |
| CVE-2026-27070 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest ... |
| CVE-2026-27068 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Websit... |
| CVE-2026-27067 | CRITICAL | 9.1 | 0.3% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa... |
| CVE-2026-27065 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25445 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This is... |
| CVE-2026-25443 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an... |
| CVE-2026-25442 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth... |
| CVE-2026-25438 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber... |
| CVE-2026-21788 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi... |
| CVE-2026-3475 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now