2026 CVE Vulnerabilities
68,768 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29516 | MEDIUM | 6.9 | 0.5% | Mar 16, 2026 | Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability... |
| CVE-2026-28430 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera... |
| CVE-2026-26304 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which ... |
| CVE-2026-32261 | HIGH | 8.5 | 0.4% | Mar 16, 2026 | Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w... |
| CVE-2026-4269 | HIGH | 7.5 | 0.2% | Mar 16, 2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a... |
| CVE-2026-4254 | CRITICAL | 9.8 | 0.9% | Mar 16, 2026 | A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of th... |
| CVE-2026-4253 | HIGH | 7.2 | 6.5% | Mar 16, 2026 | A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of th... |
| CVE-2026-4224 | HIGH | 7.5 | 0.6% | Mar 16, 2026 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply ... |
| CVE-2026-3644 | HIGH | 7.5 | 0.5% | Mar 16, 2026 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()... |
| CVE-2026-29521 | MEDIUM | 5.1 | 0.1% | Mar 16, 2026 | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows atta... |
| CVE-2026-29520 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Netwo... |
| CVE-2026-29513 | MEDIUM | 5.4 | 0.1% | Mar 16, 2026 | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut... |
| CVE-2026-29510 | MEDIUM | 5.4 | 0.1% | Mar 16, 2026 | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut... |
| CVE-2026-28498 | HIGH | 7.5 | 0.2% | Mar 16, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulne... |
| CVE-2026-28490 | MEDIUM | 6.5 | 0.1% | Mar 16, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic paddi... |
| CVE-2026-27962 | CRITICAL | 9.1 | 0.5% | Mar 16, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injectio... |
| CVE-2026-23862 | HIGH | 7.8 | 0.4% | Mar 16, 2026 | Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a C... |
| CVE-2026-23489 | CRITICAL | 9.1 | 0.3% | Mar 16, 2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possi... |
| CVE-2026-4270 | MEDIUM | 6.8 | 0.1% | Mar 16, 2026 | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= ... |
| CVE-2026-4252 | CRITICAL | 9.8 | 1.3% | Mar 16, 2026 | A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the com... |
| CVE-2026-4251 | LOW | 2.5 | 0.1% | Mar 16, 2026 | A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknow... |
| CVE-2026-30405 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute |
| CVE-2026-4276 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries. |
| CVE-2026-4250 | LOW | 2.5 | 0.1% | Mar 16, 2026 | A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an un... |
| CVE-2026-32587 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now