2026 CVE Vulnerabilities
69,027 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32334 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-32332 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-32331 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-32330 | MEDIUM | 4.3 | 0.1% | Mar 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request ... |
| CVE-2026-32329 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Ays Pro Advanced Related Posts advanced-related-posts allows Exploiting Incorrect... |
| CVE-2026-32328 | MEDIUM | 5.4 | 0.1% | Mar 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This i... |
| CVE-2026-32322 | MEDIUM | 5.3 | 0.3% | Mar 13, 2026 | soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for B... |
| CVE-2026-32320 | HIGH | 7.5 | 0.2% | Mar 13, 2026 | Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchReque... |
| CVE-2026-32319 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integ... |
| CVE-2026-32308 | HIGH | 7.6 | 0.3% | Mar 13, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component ren... |
| CVE-2026-32306 | CRITICAL | 9.9 | 0.9% | Mar 13, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API acc... |
| CVE-2026-32304 | CRITICAL | 9.8 | 0.6% | Mar 13, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat... |
| CVE-2026-32302 | HIGH | 8.1 | 0.2% | Mar 13, 2026 | OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin va... |
| CVE-2026-32301 | CRITICAL | 9.3 | 0.3% | Mar 13, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Sid... |
| CVE-2026-31949 | MEDIUM | 6.5 | 0.4% | Mar 13, 2026 | LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exist... |
| CVE-2026-31944 | HIGH | 7.6 | 0.2% | Mar 13, 2026 | LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth c... |
| CVE-2026-31922 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fo... |
| CVE-2026-31919 | MEDIUM | 4.3 | 0.3% | Mar 13, 2026 | Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-wooco... |
| CVE-2026-31918 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immonex Ki... |
| CVE-2026-31917 | HIGH | 8.5 | 0.3% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp ... |
| CVE-2026-31916 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorre... |
| CVE-2026-31915 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-31899 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se... |
| CVE-2026-31897 | CRITICAL | 9.1 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free... |
| CVE-2026-31886 | HIGH | 7.6 | 0.4% | Mar 13, 2026 | Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now