2026 CVE Vulnerabilities
67,720 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23248 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe... |
| CVE-2026-23247 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This ... |
| CVE-2026-23246 | HIGH | 8.8 | 0.3% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m... |
| CVE-2026-23245 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o... |
| CVE-2026-23244 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys() ... |
| CVE-2026-23243 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ... |
| CVE-2026-23242 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in... |
| CVE-2026-32565 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec... |
| CVE-2026-1217 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-22730 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada... |
| CVE-2026-22729 | HIGH | 8.6 | 0.5% | Mar 18, 2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass... |
| CVE-2026-22323 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ... |
| CVE-2026-22322 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica... |
| CVE-2026-22321 | MEDIUM | 5.3 | 0.4% | Mar 18, 2026 | A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a... |
| CVE-2026-22320 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel... |
| CVE-2026-22319 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs... |
| CVE-2026-22318 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at... |
| CVE-2026-22317 | HIGH | 7.2 | 1.0% | Mar 18, 2026 | A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke... |
| CVE-2026-22316 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri... |
| CVE-2026-3512 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter... |
| CVE-2026-32608 | HIGH | 7 | 0.2% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf... |
| CVE-2026-32606 | HIGH | 7.6 | 0.1% | Mar 18, 2026 | IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd... |
| CVE-2026-32596 | HIGH | 7.5 | 1.6% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent... |
| CVE-2026-32268 | HIGH | 8.7 | 0.3% | Mar 18, 2026 | The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the... |
| CVE-2026-4366 | MEDIUM | 5.8 | 0.2% | Mar 18, 2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now