2026 CVE Vulnerabilities
68,744 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3237 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change ... |
| CVE-2026-4258 | HIGH | 7.7 | 0.2% | Mar 17, 2026 | Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss... |
| CVE-2026-4308 | MEDIUM | 6.3 | 0.2% | Mar 17, 2026 | A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the ... |
| CVE-2026-4307 | MEDIUM | 4.3 | 0.4% | Mar 17, 2026 | A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element is the function get_abs_... |
| CVE-2026-2373 | MEDIUM | 5.3 | 0.2% | Mar 17, 2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Informatio... |
| CVE-2026-0708 | MEDIUM | 6.5 | 0.4% | Mar 17, 2026 | A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuratio... |
| CVE-2026-2579 | HIGH | 7.5 | 0.3% | Mar 17, 2026 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via th... |
| CVE-2026-4289 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an ... |
| CVE-2026-4288 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown... |
| CVE-2026-4287 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an un... |
| CVE-2026-4285 | LOW | 2.7 | 0.5% | Mar 17, 2026 | A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the... |
| CVE-2026-4284 | MEDIUM | 4.7 | 0.3% | Mar 16, 2026 | A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affe... |
| CVE-2026-4177 | CRITICAL | 9.1 | 0.4% | Mar 16, 2026 | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap ... |
| CVE-2026-21991 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names. |
| CVE-2026-2454 | HIGH | 8.6 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le... |
| CVE-2026-29522 | HIGH | 8.7 | 1.0% | Mar 16, 2026 | ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /serve... |
| CVE-2026-26230 | LOW | 3.8 | 0.2% | Mar 16, 2026 | Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API e... |
| CVE-2026-1629 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel acces... |
| CVE-2026-32267 | CRITICAL | 9.8 | 7.7% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R... |
| CVE-2026-32264 | HIGH | 7.2 | 0.5% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R... |
| CVE-2026-32263 | HIGH | 7.2 | 0.5% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTyp... |
| CVE-2026-32262 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R... |
| CVE-2026-30882 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scrip... |
| CVE-2026-30881 | HIGH | 8.8 | 0.3% | Mar 16, 2026 | Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the sta... |
| CVE-2026-30876 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with va... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now