2026 CVE Vulnerabilities
69,799 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30939 | HIGH | 7.5 | 0.5% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 ... |
| CVE-2026-30938 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 ... |
| CVE-2026-30934 | MEDIUM | 5.4 | 0.3% | Mar 10, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is ... |
| CVE-2026-30933 | HIGH | 7.5 | 0.5% | Mar 10, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio... |
| CVE-2026-30930 | CRITICAL | 9.8 | 0.4% | Mar 10, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module construct... |
| CVE-2026-30928 | HIGH | 7.5 | 1.7% | Mar 10, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint ret... |
| CVE-2026-30897 | MEDIUM | 6.6 | 0.6% | Mar 10, 2026 | A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, Fort... |
| CVE-2026-2742 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24... |
| CVE-2026-2741 | MEDIUM | 6.8 | 0.3% | Mar 10, 2026 | Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Va... |
| CVE-2026-2724 | HIGH | 7.2 | 0.3% | Mar 10, 2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr... |
| CVE-2026-2339 | HIGH | 7.5 | 0.8% | Mar 10, 2026 | Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li... |
| CVE-2026-2273 | HIGH | 8.2 | 0.2% | Mar 10, 2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untr... |
| CVE-2026-27661 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks co... |
| CVE-2026-26738 | HIGH | 7.8 | 0.3% | Mar 10, 2026 | Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary c... |
| CVE-2026-26148 | HIGH | 8.1 | 0.4% | Mar 10, 2026 | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate... |
| CVE-2026-26144 | MEDIUM | 4.7 | 1.2% | Mar 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an... |
| CVE-2026-26141 | HIGH | 7.8 | 0.3% | Mar 10, 2026 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26134 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26132 | HIGH | 7.8 | 2.0% | Mar 10, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26131 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26130 | HIGH | 7.5 | 2.8% | Mar 10, 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove... |
| CVE-2026-26128 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26127 | HIGH | 7.5 | 2.0% | Mar 10, 2026 | Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-26121 | HIGH | 7.5 | 1.0% | Mar 10, 2026 | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a netw... |
| CVE-2026-26118 | HIGH | 8.8 | 1.0% | Mar 10, 2026 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a networ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now