2026 CVE Vulnerabilities
68,180 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32841 | CRITICAL | 9.2 | 0.6% | Mar 17, 2026 | Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen... |
| CVE-2026-32840 | MEDIUM | 5.4 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na... |
| CVE-2026-32839 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot... |
| CVE-2026-32838 | MEDIUM | 5.9 | 0.1% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen... |
| CVE-2026-1376 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr... |
| CVE-2026-1267 | MEDIUM | 6.5 | 0.3% | Mar 17, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a... |
| CVE-2026-2809 | MEDIUM | 6.7 | 0.2% | Mar 17, 2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2026-4359 | LOW | 3.7 | 0.2% | Mar 17, 2026 | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr... |
| CVE-2026-4358 | HIGH | 7.5 | 0.3% | Mar 17, 2026 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre... |
| CVE-2026-4295 | HIGH | 8.5 | 0.2% | Mar 17, 2026 | Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una... |
| CVE-2026-4064 | HIGH | 8.3 | 0.3% | Mar 17, 2026 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen... |
| CVE-2026-3563 | MEDIUM | 5.5 | 0.3% | Mar 17, 2026 | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth... |
| CVE-2026-32981 | HIGH | 7.5 | 0.9% | Mar 17, 2026 | A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t... |
| CVE-2026-32837 | MEDIUM | 5.1 | 0.2% | Mar 17, 2026 | miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi... |
| CVE-2026-32836 | MEDIUM | 6.9 | 0.2% | Mar 17, 2026 | dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me... |
| CVE-2026-30707 | HIGH | 8.1 | 0.3% | Mar 17, 2026 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v... |
| CVE-2026-25936 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth... |
| CVE-2026-3207 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. |
| CVE-2026-25790 | HIGH | 7.2 | 0.4% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25772 | HIGH | 7.2 | 0.3% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2026-25771 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ... |
| CVE-2026-22882 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-20726 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-4319 | CRITICAL | 9.8 | 0.3% | Mar 17, 2026 | A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2026-32298 | CRITICAL | 9.1 | 0.6% | Mar 17, 2026 | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now