2026 CVE Vulnerabilities
67,727 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28673 | HIGH | 7.2 | 0.6% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-27980 | HIGH | 7.5 | 0.7% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1... |
| CVE-2026-27979 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-4355 | LOW | 3.5 | 0.2% | Mar 18, 2026 | A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_... |
| CVE-2026-4354 | LOW | 3.5 | 0.2% | Mar 18, 2026 | A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ... |
| CVE-2026-27978 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-27977 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-27895 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27894 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27811 | HIGH | 8.8 | 2.0% | Mar 18, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma... |
| CVE-2026-27459 | CRITICAL | 9.8 | 0.7% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u... |
| CVE-2026-27448 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u... |
| CVE-2026-26004 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi... |
| CVE-2026-26001 | HIGH | 8.8 | 0.2% | Mar 18, 2026 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents... |
| CVE-2026-25937 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic... |
| CVE-2026-3856 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an... |
| CVE-2026-22727 | HIGH | 7.5 | 0.2% | Mar 17, 2026 | Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a... |
| CVE-2026-21994 | CRITICAL | 9.8 | 0.4% | Mar 17, 2026 | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P... |
| CVE-2026-20643 | MEDIUM | 5.4 | 0.4% | Mar 17, 2026 | A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou... |
| CVE-2026-1264 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2026-4349 | MEDIUM | 6.3 | 0.4% | Mar 17, 2026 | A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the... |
| CVE-2026-32842 | HIGH | 7.1 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att... |
| CVE-2026-32841 | CRITICAL | 9.2 | 0.6% | Mar 17, 2026 | Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen... |
| CVE-2026-32840 | MEDIUM | 5.4 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na... |
| CVE-2026-32839 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now