2026 CVE Vulnerabilities
68,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4366 | MEDIUM | 5.8 | 0.2% | Mar 18, 2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect... |
| CVE-2026-33189 | — | — | — | Mar 18, 2026 | Rejected reason: Further research determined the issue originates from a different product. |
| CVE-2026-33188 | — | — | — | Mar 18, 2026 | Rejected reason: Further research determined the issue originates from a different product. |
| CVE-2026-33187 | — | — | — | Mar 18, 2026 | Rejected reason: Further research determined the issue originates from a different product. |
| CVE-2026-33058 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ... |
| CVE-2026-32266 | LOW | 2.4 | 0.3% | Mar 18, 2026 | The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on ... |
| CVE-2026-32265 | MEDIUM | 6.9 | 0.3% | Mar 18, 2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una... |
| CVE-2026-32256 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars... |
| CVE-2026-32254 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not... |
| CVE-2026-31938 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the... |
| CVE-2026-31898 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot... |
| CVE-2026-31891 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc... |
| CVE-2026-31865 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
| CVE-2026-30922 | HIGH | 7.5 | 0.8% | Mar 18, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ... |
| CVE-2026-30884 | CRITICAL | 9.6 | 0.2% | Mar 18, 2026 | mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi... |
| CVE-2026-2575 | MEDIUM | 5.3 | 0.7% | Mar 18, 2026 | A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS... |
| CVE-2026-29112 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic... |
| CVE-2026-1926 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2026-1780 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v... |
| CVE-2026-4356 | LOW | 2.4 | 0.2% | Mar 18, 2026 | A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add... |
| CVE-2026-4268 | MEDIUM | 6.4 | 0.2% | Mar 18, 2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm... |
| CVE-2026-2603 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ... |
| CVE-2026-2092 | HIGH | 7.7 | 0.3% | Mar 18, 2026 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val... |
| CVE-2026-29056 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat... |
| CVE-2026-28500 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now