2026 CVE Vulnerabilities
69,041 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2376 | MEDIUM | 5.4 | 0.2% | Mar 12, 2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ... |
| CVE-2026-26793 | CRITICAL | 9.8 | 2.3% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. Thi... |
| CVE-2026-3841 | HIGH | 8.8 | 1.8% | Mar 12, 2026 | A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5... |
| CVE-2026-32141 | HIGH | 7.5 | 0.8% | Mar 12, 2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve... |
| CVE-2026-32140 | HIGH | 8.8 | 0.7% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ... |
| CVE-2026-32139 | MEDIUM | 5.4 | 0.2% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload... |
| CVE-2026-32137 | HIGH | 8.8 | 0.4% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasourc... |
| CVE-2026-32129 | HIGH | 8.7 | 0.2% | Mar 12, 2026 | soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (... |
| CVE-2026-32116 | HIGH | 8.1 | 0.4% | Mar 12, 2026 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ... |
| CVE-2026-32100 | MEDIUM | 5.3 | 0.2% | Mar 12, 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul... |
| CVE-2026-31890 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-31873 | MEDIUM | 6.1 | 0.2% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin... |
| CVE-2026-31860 | MEDIUM | 6.1 | 0.3% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ... |
| CVE-2026-28256 | CRITICAL | 9.8 | 0.3% | Mar 12, 2026 | A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge coul... |
| CVE-2026-28255 | CRITICAL | 9.8 | 0.3% | Mar 12, 2026 | A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attack... |
| CVE-2026-28254 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate... |
| CVE-2026-28253 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a... |
| CVE-2026-28252 | CRITICAL | 9.8 | 0.2% | Mar 12, 2026 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge co... |
| CVE-2026-26795 | CRITICAL | 9.8 | 2.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the ... |
| CVE-2026-26794 | HIGH | 8.8 | 0.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v... |
| CVE-2026-26792 | CRITICAL | 9.8 | 2.8% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade func... |
| CVE-2026-26791 | CRITICAL | 9.8 | 2.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in... |
| CVE-2026-4045 | LOW | 3.7 | 0.3% | Mar 12, 2026 | A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php... |
| CVE-2026-31841 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0... |
| CVE-2026-29066 | MEDIUM | 6.2 | 1.0% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now