2026 CVE Vulnerabilities
69,853 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28433 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but ... |
| CVE-2026-28432 | HIGH | 7.5 | 0.1% | Mar 10, 2026 | Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit... |
| CVE-2026-28431 | HIGH | 7.5 | 0.2% | Mar 10, 2026 | Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p... |
| CVE-2026-26982 | HIGH | 8.8 | 0.3% | Mar 10, 2026 | Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dro... |
| CVE-2026-1776 | MEDIUM | 6.5 | 0.8% | Mar 10, 2026 | Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS ... |
| CVE-2026-3288 | HIGH | 8.8 | 6.7% | Mar 9, 2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati... |
| CVE-2026-31816 | CRITICAL | 9.1 | 15.3% | Mar 9, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Bud... |
| CVE-2026-30240 | HIGH | 8.1 | 0.3% | Mar 9, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path ... |
| CVE-2026-25960 | CRITICAL | 9.8 | 0.5% | Mar 9, 2026 | vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add... |
| CVE-2026-25737 | CRITICAL | 9 | 0.3% | Mar 9, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbi... |
| CVE-2026-25045 | HIGH | 8.8 | 0.3% | Mar 9, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of... |
| CVE-2026-25041 | HIGH | 7.2 | 0.5% | Mar 9, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po... |
| CVE-2026-0846 | HIGH | 7.5 | 0.4% | Mar 9, 2026 | A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea... |
| CVE-2026-3638 | MEDIUM | 5.9 | 0.2% | Mar 9, 2026 | Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo... |
| CVE-2026-30140 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t... |
| CVE-2026-29023 | HIGH | 7.3 | 0.2% | Mar 9, 2026 | Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled an... |
| CVE-2026-3588 | MEDIUM | 5.5 | 0.1% | Mar 9, 2026 | A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke... |
| CVE-2026-25866 | HIGH | 8.5 | 0.1% | Mar 9, 2026 | MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExe... |
| CVE-2026-3089 | MEDIUM | 6.5 | 0.4% | Mar 9, 2026 | Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to ... |
| CVE-2026-2919 | MEDIUM | 4.3 | 0.2% | Mar 9, 2026 | Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se... |
| CVE-2026-3819 | MEDIUM | 5.4 | 0.3% | Mar 9, 2026 | A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown funct... |
| CVE-2026-3038 | HIGH | 7.5 | 0.5% | Mar 9, 2026 | The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st... |
| CVE-2026-2261 | HIGH | 7.5 | 0.4% | Mar 9, 2026 | Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert... |
| CVE-2026-21736 | MEDIUM | 4.4 | 0.1% | Mar 9, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re... |
| CVE-2026-3818 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebSer... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now