2026 CVE Vulnerabilities
69,036 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32259 | MEDIUM | 6.7 | 0.1% | Mar 12, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9... |
| CVE-2026-32251 | MEDIUM | 6.5 | 0.4% | Mar 12, 2026 | Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc... |
| CVE-2026-32249 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun... |
| CVE-2026-32248 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32240 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: ... |
| CVE-2026-32239 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu... |
| CVE-2026-1525 | CRITICAL | 9.8 | 0.5% | Mar 12, 2026 | Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Co... |
| CVE-2026-3497 | HIGH | 7.5 | 2.2% | Mar 12, 2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI... |
| CVE-2026-32247 | HIGH | 8.1 | 0.3% | Mar 12, 2026 | Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2... |
| CVE-2026-32246 | HIGH | 7.1 | 0.3% | Mar 12, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit... |
| CVE-2026-32245 | MEDIUM | 6.5 | 0.3% | Mar 12, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the... |
| CVE-2026-32242 | HIGH | 7.4 | 0.3% | Mar 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32237 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex... |
| CVE-2026-32236 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul... |
| CVE-2026-32235 | MEDIUM | 4.7 | 0.1% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs... |
| CVE-2026-32232 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Valid... |
| CVE-2026-32231 | HIGH | 8.2 | 0.2% | Mar 12, 2026 | ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields... |
| CVE-2026-32230 | MEDIUM | 5.3 | 0.9% | Mar 12, 2026 | Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?... |
| CVE-2026-32142 | MEDIUM | 5.3 | 0.2% | Mar 12, 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is... |
| CVE-2026-32138 | HIGH | 8.2 | 0.3% | Mar 12, 2026 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P... |
| CVE-2026-2376 | MEDIUM | 5.4 | 0.2% | Mar 12, 2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ... |
| CVE-2026-26793 | CRITICAL | 9.8 | 2.3% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. Thi... |
| CVE-2026-3841 | HIGH | 8.8 | 1.8% | Mar 12, 2026 | A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5... |
| CVE-2026-32141 | HIGH | 7.5 | 0.8% | Mar 12, 2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve... |
| CVE-2026-32140 | HIGH | 8.8 | 0.7% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now