2026 CVE Vulnerabilities
69,057 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21672 | HIGH | 8.8 | 0.2% | Mar 12, 2026 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. |
| CVE-2026-4044 | LOW | 3.8 | 0.4% | Mar 12, 2026 | A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.... |
| CVE-2026-4043 | HIGH | 8.8 | 0.6% | Mar 12, 2026 | A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDg... |
| CVE-2026-4042 | HIGH | 8.8 | 0.8% | Mar 12, 2026 | A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of ... |
| CVE-2026-4041 | HIGH | 8.8 | 0.8% | Mar 12, 2026 | A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/... |
| CVE-2026-28384 | CRITICAL | 9.9 | 0.6% | Mar 12, 2026 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged u... |
| CVE-2026-21671 | CRITICAL | 9.1 | 1.3% | Mar 12, 2026 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE)... |
| CVE-2026-21670 | MEDIUM | 6.5 | 0.4% | Mar 12, 2026 | A vulnerability allowing a low-privileged user to extract saved SSH credentials. |
| CVE-2026-21669 | CRITICAL | 9.9 | 1.2% | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| CVE-2026-21668 | MEDIUM | 6.5 | 0.5% | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup ... |
| CVE-2026-21667 | HIGH | 8.8 | 1.1% | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| CVE-2026-21666 | HIGH | 8.8 | 1.1% | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| CVE-2026-3099 | HIGH | 7.3 | 0.4% | Mar 12, 2026 | A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does... |
| CVE-2026-2987 | MEDIUM | 6.1 | 0.2% | Mar 12, 2026 | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions... |
| CVE-2026-2514 | MEDIUM | 6.1 | 0.2% | Mar 12, 2026 | In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to ... |
| CVE-2026-2513 | MEDIUM | 6.1 | 0.3% | Mar 12, 2026 | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks ... |
| CVE-2026-0809 | MEDIUM | 6.3 | 0.2% | Mar 12, 2026 | Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-F... |
| CVE-2026-4040 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c... |
| CVE-2026-4039 | HIGH | 8.8 | 0.3% | Mar 12, 2026 | A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr... |
| CVE-2026-3989 | HIGH | 7.8 | 0.3% | Mar 12, 2026 | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at... |
| CVE-2026-3060 | CRITICAL | 9.8 | 1.2% | Mar 12, 2026 | SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disagg... |
| CVE-2026-3059 | CRITICAL | 9.8 | 1.5% | Mar 12, 2026 | SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, whi... |
| CVE-2026-3234 | MEDIUM | 4.3 | 0.3% | Mar 12, 2026 | A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen... |
| CVE-2026-2366 | LOW | 3.1 | 0.3% | Mar 12, 2026 | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u... |
| CVE-2026-4016 | MEDIUM | 5.3 | 0.1% | Mar 12, 2026 | A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_proce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now