2026 CVE Vulnerabilities
69,831 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23669 | HIGH | 8.8 | 0.9% | Mar 10, 2026 | Use after free in RPC Runtime allows an authorized attacker to execute code over a network. |
| CVE-2026-23668 | HIGH | 7 | 3.6% | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon... |
| CVE-2026-23667 | HIGH | 7 | 0.3% | Mar 10, 2026 | Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. |
| CVE-2026-23665 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. |
| CVE-2026-23664 | HIGH | 7.5 | 1.0% | Mar 10, 2026 | Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke... |
| CVE-2026-23662 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati... |
| CVE-2026-23661 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose inform... |
| CVE-2026-23660 | HIGH | 7.8 | 0.3% | Mar 10, 2026 | Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally... |
| CVE-2026-23656 | MEDIUM | 5.9 | 0.3% | Mar 10, 2026 | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof... |
| CVE-2026-23654 | HIGH | 8.8 | 0.9% | Mar 10, 2026 | Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to... |
| CVE-2026-23240 | CRITICAL | 9.8 | 0.5% | Mar 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() ... |
| CVE-2026-23239 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() T... |
| CVE-2026-22629 | LOW | 3.7 | 0.4% | Mar 10, 2026 | An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4... |
| CVE-2026-22628 | MEDIUM | 6.7 | 0.1% | Mar 10, 2026 | An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a... |
| CVE-2026-22627 | HIGH | 8.8 | 0.3% | Mar 10, 2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.... |
| CVE-2026-22614 | MEDIUM | 6.1 | 0.1% | Mar 10, 2026 | The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a... |
| CVE-2026-22572 | HIGH | 7.2 | 0.6% | Mar 10, 2026 | An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,... |
| CVE-2026-21791 | LOW | 3.3 | 0.1% | Mar 10, 2026 | HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica... |
| CVE-2026-21262 | HIGH | 8.8 | 2.0% | Mar 10, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-20967 | HIGH | 8.8 | 1.1% | Mar 10, 2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a... |
| CVE-2026-1286 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an... |
| CVE-2026-1261 | HIGH | 7.2 | 0.3% | Mar 10, 2026 | The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions u... |
| CVE-2026-3585 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.... |
| CVE-2026-30927 | MEDIUM | 5.4 | 0.3% | Mar 10, 2026 | Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event par... |
| CVE-2026-30925 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now