2026 CVE Vulnerabilities
69,141 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32234 | MEDIUM | 4.7 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32098 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32097 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat... |
| CVE-2026-32096 | HIGH | 8.6 | 0.3% | Mar 11, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vul... |
| CVE-2026-32095 | MEDIUM | 5.4 | 0.1% | Mar 11, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted S... |
| CVE-2026-32094 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-brac... |
| CVE-2026-31979 | HIGH | 7.8 | 0.2% | Mar 11, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla... |
| CVE-2026-31976 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credenti... |
| CVE-2026-31974 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P... |
| CVE-2026-31961 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb... |
| CVE-2026-31960 | MEDIUM | 5.3 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded r... |
| CVE-2026-31959 | MEDIUM | 5.3 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Serv... |
| CVE-2026-31958 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only l... |
| CVE-2026-31957 | CRITICAL | 10 | 0.5% | Mar 11, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelbl... |
| CVE-2026-31954 | HIGH | 7.3 | 0.1% | Mar 11, 2026 | Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lac... |
| CVE-2026-31901 | MEDIUM | 5.3 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 ... |
| CVE-2026-31900 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo... |
| CVE-2026-31896 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exist... |
| CVE-2026-31895 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições ass... |
| CVE-2026-31894 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a t... |
| CVE-2026-31889 | HIGH | 8.9 | 0.3% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ... |
| CVE-2026-27703 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2026-27478 | CRITICAL | 9.1 | 0.2% | Mar 11, 2026 | Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu... |
| CVE-2026-24510 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit... |
| CVE-2026-24508 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now