2026 CVE Vulnerabilities
68,809 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3020 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user... |
| CVE-2026-32778 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo... |
| CVE-2026-32777 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. |
| CVE-2026-32776 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. |
| CVE-2026-32775 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 s... |
| CVE-2026-32774 | MEDIUM | 5.4 | 0.3% | Mar 16, 2026 | Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers... |
| CVE-2026-32772 | MEDIUM | 4.7 | 0.2% | Mar 16, 2026 | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON ... |
| CVE-2026-32732 | NONE | 0 | 0.3% | Mar 16, 2026 | Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover... |
| CVE-2026-32729 | HIGH | 8.8 | 0.3% | Mar 16, 2026 | Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor... |
| CVE-2026-32724 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the Mav... |
| CVE-2026-32720 | HIGH | 7.1 | 0.3% | Mar 16, 2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met... |
| CVE-2026-32719 | MEDIUM | 6.4 | 0.4% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32717 | LOW | 2.7 | 0.2% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32715 | LOW | 3.8 | 0.2% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32713 | MEDIUM | 6.5 | 0.4% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink F... |
| CVE-2026-32709 | MEDIUM | 6.8 | 0.5% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerabil... |
| CVE-2026-32708 | HIGH | 8 | 0.2% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack ... |
| CVE-2026-32707 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it... |
| CVE-2026-32706 | HIGH | 8.1 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari... |
| CVE-2026-32705 | MEDIUM | 6.8 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term... |
| CVE-2026-32704 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR... |
| CVE-2026-32702 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-32640 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu... |
| CVE-2026-32635 | CRITICAL | 9 | 0.3% | Mar 16, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-32630 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now