2026 CVE Vulnerabilities
69,057 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32100 | MEDIUM | 5.3 | 0.2% | Mar 12, 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul... |
| CVE-2026-31890 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-31873 | MEDIUM | 6.1 | 0.2% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin... |
| CVE-2026-31860 | MEDIUM | 6.1 | 0.3% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ... |
| CVE-2026-28256 | CRITICAL | 9.8 | 0.3% | Mar 12, 2026 | A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge coul... |
| CVE-2026-28255 | CRITICAL | 9.8 | 0.3% | Mar 12, 2026 | A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attack... |
| CVE-2026-28254 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate... |
| CVE-2026-28253 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a... |
| CVE-2026-28252 | CRITICAL | 9.8 | 0.2% | Mar 12, 2026 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge co... |
| CVE-2026-26795 | CRITICAL | 9.8 | 2.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the ... |
| CVE-2026-26794 | HIGH | 8.8 | 0.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v... |
| CVE-2026-26792 | CRITICAL | 9.8 | 2.8% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade func... |
| CVE-2026-26791 | CRITICAL | 9.8 | 2.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in... |
| CVE-2026-4045 | LOW | 3.7 | 0.3% | Mar 12, 2026 | A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php... |
| CVE-2026-31841 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0... |
| CVE-2026-29066 | MEDIUM | 6.2 | 1.0% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.... |
| CVE-2026-28793 | HIGH | 8.4 | 0.2% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints... |
| CVE-2026-28792 | CRITICAL | 9.6 | 0.5% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS con... |
| CVE-2026-28791 | HIGH | 7.4 | 0.3% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel... |
| CVE-2026-28356 | HIGH | 7.5 | 0.7% | Mar 12, 2026 | multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header... |
| CVE-2026-27940 | HIGH | 7.8 | 0.2% | Mar 12, 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ... |
| CVE-2026-25529 | HIGH | 8.1 | 0.2% | Mar 12, 2026 | Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un... |
| CVE-2026-24125 | MEDIUM | 6.3 | 0.4% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content... |
| CVE-2026-21887 | HIGH | 7.7 | 0.2% | Mar 12, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, th... |
| CVE-2026-21708 | CRITICAL | 9.9 | 1.1% | Mar 12, 2026 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now