2026 CVE Vulnerabilities
69,544 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31832 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability ex... |
| CVE-2026-31830 | HIGH | 7.5 | 0.2% | Mar 10, 2026 | sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.... |
| CVE-2026-31829 | HIGH | 8.8 | 2.3% | Mar 10, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise expose... |
| CVE-2026-31828 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-31827 | HIGH | 7.1 | 0.2% | Mar 10, 2026 | Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops ... |
| CVE-2026-31826 | MEDIUM | 5.5 | 0.2% | Mar 10, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra... |
| CVE-2026-31825 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder... |
| CVE-2026-31824 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was disc... |
| CVE-2026-31823 | MEDIUM | 4.8 | 0.1% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerabilit... |
| CVE-2026-31822 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop c... |
| CVE-2026-31821 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does n... |
| CVE-2026-31820 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner... |
| CVE-2026-31819 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserContro... |
| CVE-2026-31817 | HIGH | 8.5 | 0.7% | Mar 10, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature i... |
| CVE-2026-31815 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula... |
| CVE-2026-31812 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u... |
| CVE-2026-28807 | HIGH | 7.5 | 1.1% | Mar 10, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows a... |
| CVE-2026-28806 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bu... |
| CVE-2026-27278 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil... |
| CVE-2026-27221 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val... |
| CVE-2026-27220 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil... |
| CVE-2026-31809 | MEDIUM | 6.1 | 0.5% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attr... |
| CVE-2026-31808 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in... |
| CVE-2026-31807 | MEDIUM | 6.1 | 0.4% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous... |
| CVE-2026-31801 | HIGH | 7.7 | 0.2% | Mar 10, 2026 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now