2026 CVE Vulnerabilities
68,730 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24063 | HIGH | 8.2 | 0.1% | Mar 18, 2026 | When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a ... |
| CVE-2026-24062 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu... |
| CVE-2026-32609 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenti... |
| CVE-2026-3278 | MEDIUM | 6.1 | 0.1% | Mar 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks... |
| CVE-2026-32694 | MEDIUM | 6.6 | 0.3% | Mar 18, 2026 | In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret o... |
| CVE-2026-25449 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affec... |
| CVE-2026-32693 | HIGH | 8.8 | 0.3% | Mar 18, 2026 | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which ... |
| CVE-2026-32692 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18... |
| CVE-2026-32691 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit ... |
| CVE-2026-33265 | CRITICAL | 9 | 0.2% | Mar 18, 2026 | In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API. |
| CVE-2026-23248 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe... |
| CVE-2026-23247 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This ... |
| CVE-2026-23246 | HIGH | 8.8 | 0.3% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m... |
| CVE-2026-23245 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o... |
| CVE-2026-23244 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys() ... |
| CVE-2026-23243 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ... |
| CVE-2026-23242 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in... |
| CVE-2026-32565 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec... |
| CVE-2026-1217 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-22730 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada... |
| CVE-2026-22729 | HIGH | 8.6 | 0.5% | Mar 18, 2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass... |
| CVE-2026-22323 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ... |
| CVE-2026-22322 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica... |
| CVE-2026-22321 | MEDIUM | 5.3 | 0.4% | Mar 18, 2026 | A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a... |
| CVE-2026-22320 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now