2026 CVE Vulnerabilities
69,030 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31899 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se... |
| CVE-2026-31897 | CRITICAL | 9.1 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free... |
| CVE-2026-31886 | HIGH | 7.6 | 0.4% | Mar 13, 2026 | Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the... |
| CVE-2026-31885 | CRITICAL | 9.4 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-A... |
| CVE-2026-31884 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-A... |
| CVE-2026-31883 | CRITICAL | 9.8 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM an... |
| CVE-2026-31882 | HIGH | 7.5 | 0.8% | Mar 13, 2026 | Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic au... |
| CVE-2026-31864 | MEDIUM | 6.8 | 0.3% | Mar 13, 2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template... |
| CVE-2026-31814 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a special... |
| CVE-2026-31806 | CRITICAL | 9.8 | 0.7% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function proce... |
| CVE-2026-31798 | MEDIUM | 5 | 0.1% | Mar 13, 2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,... |
| CVE-2026-30961 | MEDIUM | 4.3 | 0.3% | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunke... |
| CVE-2026-30955 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API end... |
| CVE-2026-30943 | MEDIUM | 4.1 | 0.2% | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insuffi... |
| CVE-2026-30915 | MEDIUM | 4.3 | 0.3% | Mar 13, 2026 | SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation... |
| CVE-2026-30914 | HIGH | 8.1 | 0.5% | Mar 13, 2026 | SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization d... |
| CVE-2026-30853 | HIGH | 8.2 | 0.2% | Mar 13, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p... |
| CVE-2026-2890 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi... |
| CVE-2026-2888 | MEDIUM | 5.3 | 0.4% | Mar 13, 2026 | The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve... |
| CVE-2026-2879 | MEDIUM | 5.4 | 0.3% | Mar 13, 2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including... |
| CVE-2026-2859 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows... |
| CVE-2026-2673 | MEDIUM | 6.5 | 0.4% | Mar 13, 2026 | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key ex... |
| CVE-2026-2257 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including... |
| CVE-2026-29776 | LOW | 3.1 | 0.2% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache... |
| CVE-2026-29775 | HIGH | 8.2 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now