2026 CVE Vulnerabilities
67,770 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25534 | CRITICAL | 9.1 | 0.2% | Mar 17, 2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri... |
| CVE-2026-21570 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ... |
| CVE-2026-4148 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu... |
| CVE-2026-4147 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-28506 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for... |
| CVE-2026-24901 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I... |
| CVE-2026-23759 | HIGH | 8.6 | 1.5% | Mar 17, 2026 | Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ... |
| CVE-2026-21886 | HIGH | 8.1 | 0.2% | Mar 17, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2026-4318 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform... |
| CVE-2026-3564 | CRITICAL | 9 | 0.4% | Mar 17, 2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ... |
| CVE-2026-4324 | MEDIUM | 5.4 | 0.3% | Mar 17, 2026 | A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use... |
| CVE-2026-3888 | HIGH | 7.8 | 0.4% | Mar 17, 2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ... |
| CVE-2026-4271 | HIGH | 7.5 | 0.8% | Mar 17, 2026 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs... |
| CVE-2026-30911 | HIGH | 8.1 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop... |
| CVE-2026-28779 | HIGH | 7.5 | 0.7% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu... |
| CVE-2026-28563 | MEDIUM | 4.3 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt... |
| CVE-2026-26929 | MEDIUM | 6.5 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin... |
| CVE-2026-3634 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage... |
| CVE-2026-3633 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function... |
| CVE-2026-3632 | MEDIUM | 5.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ... |
| CVE-2026-23241 | MEDIUM | 5.5 | 0.1% | Mar 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"... |
| CVE-2026-4208 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M... |
| CVE-2026-4202 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of ... |
| CVE-2026-32586 | MEDIUM | 5.3 | 0.2% | Mar 17, 2026 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl... |
| CVE-2026-1323 | HIGH | 8.8 | 0.2% | Mar 17, 2026 | The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now