2026 CVE Vulnerabilities
67,740 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30707 | HIGH | 8.1 | 0.3% | Mar 17, 2026 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v... |
| CVE-2026-25936 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth... |
| CVE-2026-3207 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. |
| CVE-2026-25790 | HIGH | 7.2 | 0.4% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25772 | HIGH | 7.2 | 0.3% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2026-25771 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ... |
| CVE-2026-22882 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-20726 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-4319 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-32298 | CRITICAL | 9.1 | 0.6% | Mar 17, 2026 | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen... |
| CVE-2026-32297 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ... |
| CVE-2026-32296 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent... |
| CVE-2026-32295 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. |
| CVE-2026-32294 | HIGH | 7 | 0.1% | Mar 17, 2026 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp... |
| CVE-2026-32293 | MEDIUM | 6.3 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL... |
| CVE-2026-32292 | CRITICAL | 9.3 | 0.5% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede... |
| CVE-2026-32291 | HIGH | 7 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ... |
| CVE-2026-32290 | HIGH | 7 | 0.2% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f... |
| CVE-2026-25770 | HIGH | 7.2 | 1.0% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25769 | CRITICAL | 9.1 | 9.2% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1... |
| CVE-2026-25534 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri... |
| CVE-2026-21570 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ... |
| CVE-2026-4148 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu... |
| CVE-2026-4147 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-28506 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now