2026 CVE Vulnerabilities
69,033 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2257 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including... |
| CVE-2026-29776 | LOW | 3.1 | 0.2% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache... |
| CVE-2026-29775 | HIGH | 8.2 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/... |
| CVE-2026-29774 | HIGH | 8.2 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occ... |
| CVE-2026-29079 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment ... |
| CVE-2026-29078 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s... |
| CVE-2026-26954 | CRITICAL | 10 | 0.5% | Mar 13, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, whic... |
| CVE-2026-25823 | CRITICAL | 9.8 | 0.7% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25819 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25818 | CRITICAL | 9.1 | 0.1% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25817 | HIGH | 8.8 | 0.8% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25076 | HIGH | 8.5 | 0.3% | Mar 13, 2026 | Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenti... |
| CVE-2026-24097 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows... |
| CVE-2026-23943 | MEDIUM | 5.3 | 0.6% | Mar 13, 2026 | Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) a... |
| CVE-2026-23942 | MEDIUM | 5.4 | 0.4% | Mar 13, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd mo... |
| CVE-2026-23941 | CRITICAL | 9.4 | 0.5% | Mar 13, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module)... |
| CVE-2026-23940 | MEDIUM | 6.5 | 0.4% | Mar 13, 2026 | Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversiz... |
| CVE-2026-22216 | MEDIUM | 5.3 | 0.3% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe... |
| CVE-2026-22215 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows ... |
| CVE-2026-22210 | MEDIUM | 6.1 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thro... |
| CVE-2026-22209 | MEDIUM | 5.5 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators t... |
| CVE-2026-22204 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipie... |
| CVE-2026-22203 | MEDIUM | 6.9 | 0.3% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expo... |
| CVE-2026-22202 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments ... |
| CVE-2026-22201 | MEDIUM | 6.9 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now