2026 CVE Vulnerabilities
68,833 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20991 | MEDIUM | 4.4 | 0.1% | Mar 16, 2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse... |
| CVE-2026-20990 | HIGH | 8.1 | 0.2% | Mar 16, 2026 | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attacker... |
| CVE-2026-20989 | LOW | 2.4 | 0.1% | Mar 16, 2026 | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attack... |
| CVE-2026-20988 | MEDIUM | 5 | 0.1% | Mar 16, 2026 | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker ... |
| CVE-2026-1948 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2026-1947 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Referen... |
| CVE-2026-1883 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Inse... |
| CVE-2026-1870 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthori... |
| CVE-2026-0977 | HIGH | 7.1 | 0.2% | Mar 16, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope... |
| CVE-2026-0849 | MEDIUM | 6.8 | 0.2% | Mar 16, 2026 | Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver... |
| CVE-2026-0639 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2026-0385 | MEDIUM | 5 | 0.2% | Mar 16, 2026 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-4111 | HIGH | 7.5 | 0.7% | Mar 13, 2026 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive... |
| CVE-2026-4105 | MEDIUM | 6.7 | 0.1% | Mar 13, 2026 | A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf... |
| CVE-2026-4092 | HIGH | 8.8 | 0.5% | Mar 13, 2026 | Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic... |
| CVE-2026-4063 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ... |
| CVE-2026-3999 | HIGH | 8.8 | 0.3% | Mar 13, 2026 | A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability... |
| CVE-2026-3986 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al... |
| CVE-2026-3910 | HIGH | 8.8 | 2.0% | Mar 13, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar... |
| CVE-2026-3909 | HIGH | 8.8 | 1.6% | Mar 13, 2026 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m... |
| CVE-2026-3891 | CRITICAL | 9.8 | 0.8% | Mar 13, 2026 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and... |
| CVE-2026-3873 | HIGH | 7.2 | 0.2% | Mar 13, 2026 | Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs.... |
| CVE-2026-3045 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2026-32746 | CRITICAL | 9.8 | 23.7% | Mar 13, 2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ... |
| CVE-2026-32745 | MEDIUM | 5.7 | 0.1% | Mar 13, 2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now