2026 CVE Vulnerabilities
69,292 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24508 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil... |
| CVE-2026-3949 | LOW | 3.3 | 0.1% | Mar 11, 2026 | A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the fil... |
| CVE-2026-31888 | MEDIUM | 5.3 | 0.2% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc... |
| CVE-2026-31887 | HIGH | 7.5 | 0.2% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for una... |
| CVE-2026-31881 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin... |
| CVE-2026-31879 | MEDIUM | 5.4 | 0.1% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation ... |
| CVE-2026-31878 | MEDIUM | 5 | 0.2% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a... |
| CVE-2026-31877 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce... |
| CVE-2026-31876 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS... |
| CVE-2026-31874 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the ... |
| CVE-2026-24509 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l... |
| CVE-2026-31975 | CRITICAL | 9.8 | 3.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31875 | MEDIUM | 5.9 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31872 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31871 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31870 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl... |
| CVE-2026-31868 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31867 | MEDIUM | 4.8 | 0.3% | Mar 11, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I... |
| CVE-2026-31866 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and... |
| CVE-2026-31863 | MEDIUM | 4.4 | 0.1% | Mar 11, 2026 | Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca... |
| CVE-2026-31862 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31861 | HIGH | 8.8 | 6.0% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31859 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in... |
| CVE-2026-31858 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ... |
| CVE-2026-31857 | HIGH | 8.8 | 0.7% | Mar 11, 2026 | Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now