2026 CVE Vulnerabilities
68,850 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0977 | HIGH | 7.1 | 0.2% | Mar 16, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope... |
| CVE-2026-0849 | MEDIUM | 6.8 | 0.2% | Mar 16, 2026 | Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver... |
| CVE-2026-0639 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2026-0385 | MEDIUM | 5 | 0.2% | Mar 16, 2026 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-4111 | HIGH | 7.5 | 0.7% | Mar 13, 2026 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive... |
| CVE-2026-4105 | MEDIUM | 6.7 | 0.1% | Mar 13, 2026 | A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insuf... |
| CVE-2026-4092 | HIGH | 8.8 | 0.5% | Mar 13, 2026 | Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic... |
| CVE-2026-4063 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ... |
| CVE-2026-3999 | HIGH | 8.8 | 0.3% | Mar 13, 2026 | A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability... |
| CVE-2026-3986 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al... |
| CVE-2026-3910 | HIGH | 8.8 | 2.0% | Mar 13, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar... |
| CVE-2026-3909 | HIGH | 8.8 | 1.6% | Mar 13, 2026 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m... |
| CVE-2026-3891 | CRITICAL | 9.8 | 0.8% | Mar 13, 2026 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and... |
| CVE-2026-3873 | HIGH | 7.2 | 0.2% | Mar 13, 2026 | Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs.... |
| CVE-2026-3045 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2026-32746 | CRITICAL | 9.8 | 23.7% | Mar 13, 2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ... |
| CVE-2026-32745 | MEDIUM | 5.7 | 0.1% | Mar 13, 2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings |
| CVE-2026-32612 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel c... |
| CVE-2026-32598 | MEDIUM | 6.5 | 0.3% | Mar 13, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the ... |
| CVE-2026-32597 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header ... |
| CVE-2026-32543 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting In... |
| CVE-2026-32487 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly C... |
| CVE-2026-32486 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Config... |
| CVE-2026-32462 | MEDIUM | 5.9 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste... |
| CVE-2026-32461 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incor... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now