2026 CVE Vulnerabilities
68,816 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32706 | HIGH | 8.1 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari... |
| CVE-2026-32705 | MEDIUM | 6.8 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term... |
| CVE-2026-32704 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR... |
| CVE-2026-32702 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-32640 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu... |
| CVE-2026-32635 | CRITICAL | 9 | 0.3% | Mar 16, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-32630 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess... |
| CVE-2026-32628 | HIGH | 8.8 | 0.3% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32627 | HIGH | 8.1 | 0.2% | Mar 16, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib cl... |
| CVE-2026-32626 | CRITICAL | 9.6 | 0.7% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32621 | CRITICAL | 9.9 | 0.5% | Mar 16, 2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11... |
| CVE-2026-32617 | HIGH | 7.5 | 0.4% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32616 | HIGH | 8.2 | 0.2% | Mar 16, 2026 | Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] witho... |
| CVE-2026-32614 | HIGH | 7.5 | 0.2% | Mar 16, 2026 | Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial crypto... |
| CVE-2026-32600 | HIGH | 8.2 | 0.1% | Mar 16, 2026 | xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes e... |
| CVE-2026-32594 | HIGH | 7.3 | 0.3% | Mar 16, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 ... |
| CVE-2026-32314 | HIGH | 7.5 | 0.5% | Mar 16, 2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementati... |
| CVE-2026-32313 | HIGH | 8.2 | 0.2% | Mar 16, 2026 | xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypt... |
| CVE-2026-31386 | HIGH | 8.6 | 1.5% | Mar 16, 2026 | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An a... |
| CVE-2026-2923 | HIGH | 7.8 | 0.7% | Mar 16, 2026 | GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-2922 | HIGH | 7.8 | 0.4% | Mar 16, 2026 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2026-2921 | HIGH | 7.8 | 0.9% | Mar 16, 2026 | GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ... |
| CVE-2026-2920 | HIGH | 7.8 | 0.8% | Mar 16, 2026 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-2578 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which all... |
| CVE-2026-2493 | HIGH | 7.5 | 3.9% | Mar 16, 2026 | IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now