2026 CVE Vulnerabilities
69,550 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29113 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token e... |
| CVE-2026-28495 | HIGH | 8.8 | 0.3% | Mar 10, 2026 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo... |
| CVE-2026-27825 | HIGH | 8 | 2.3% | Mar 10, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.... |
| CVE-2026-26330 | HIGH | 7.5 | 0.3% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit f... |
| CVE-2026-26311 | MEDIUM | 5.9 | 0.3% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerabili... |
| CVE-2026-26310 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge... |
| CVE-2026-26309 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write... |
| CVE-2026-26308 | HIGH | 8.2 | 0.3% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Rol... |
| CVE-2026-26123 | MEDIUM | 5.5 | 0.6% | Mar 10, 2026 | Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. |
| CVE-2026-23868 | MEDIUM | 5.1 | 0.1% | Mar 10, 2026 | Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro... |
| CVE-2026-3370 | — | — | — | Mar 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-28292 | CRITICAL | 9.8 | 1.3% | Mar 10, 2026 | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through ... |
| CVE-2026-27826 | HIGH | 8.2 | 13.6% | Mar 10, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.... |
| CVE-2026-27281 | MEDIUM | 5.5 | 0.2% | Mar 10, 2026 | DNG SDK versions 1.7.1 2471 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead ... |
| CVE-2026-27280 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr... |
| CVE-2026-27279 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-27277 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2026-27276 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2026-27275 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-27274 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-27273 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-27269 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ... |
| CVE-2026-27219 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to... |
| CVE-2026-27218 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le... |
| CVE-2026-27217 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now