2026 CVE Vulnerabilities
67,521 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32737 | CRITICAL | 10 | 0.4% | Mar 18, 2026 | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function... |
| CVE-2026-32736 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object... |
| CVE-2026-32735 | LOW | 2.3 | 0.3% | Mar 18, 2026 | openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i... |
| CVE-2026-32731 | CRITICAL | 9.9 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ... |
| CVE-2026-32730 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m... |
| CVE-2026-4407 | LOW | 2.1 | 0.1% | Mar 18, 2026 | Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space... |
| CVE-2026-33163 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-33042 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32944 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32943 | LOW | 3.1 | 0.2% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32886 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32878 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32770 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32742 | MEDIUM | 4.3 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32728 | HIGH | 7.6 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32723 | MEDIUM | 4.7 | 0.1% | Mar 18, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global... |
| CVE-2026-32722 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process ... |
| CVE-2026-32703 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 1... |
| CVE-2026-32698 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2... |
| CVE-2026-32700 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Con... |
| CVE-2026-32638 | LOW | 2.7 | 0.4% | Mar 18, 2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get... |
| CVE-2026-32636 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9... |
| CVE-2026-32321 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability ex... |
| CVE-2026-31973 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th... |
| CVE-2026-31972 | CRITICAL | 9.8 | 0.5% | Mar 18, 2026 | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now