2026 CVE Vulnerabilities
70,015 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28284 | HIGH | 8.8 | 0.2% | Mar 5, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several aut... |
| CVE-2026-28210 | HIGH | 8.8 | 0.3% | Mar 5, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnera... |
| CVE-2026-28209 | HIGH | 7.2 | 0.9% | Mar 5, 2026 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ... |
| CVE-2026-27944 | CRITICAL | 9.8 | 22.2% | Mar 5, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessibl... |
| CVE-2026-27723 | MEDIUM | 5.3 | 0.2% | Mar 5, 2026 | OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c... |
| CVE-2026-27023 | MEDIUM | 5 | 0.2% | Mar 5, 2026 | Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR... |
| CVE-2026-26999 | HIGH | 7.5 | 0.5% | Mar 5, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil... |
| CVE-2026-26998 | MEDIUM | 4.4 | 0.5% | Mar 5, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil... |
| CVE-2026-26418 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem... |
| CVE-2026-26417 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Clie... |
| CVE-2026-26416 | HIGH | 8.8 | 0.4% | Mar 5, 2026 | An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users t... |
| CVE-2026-26276 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa... |
| CVE-2026-26196 | MEDIUM | 5.3 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik... |
| CVE-2026-26195 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem... |
| CVE-2026-26194 | HIGH | 7.3 | 0.4% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting... |
| CVE-2026-26022 | MEDIUM | 5.4 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili... |
| CVE-2026-25921 | CRITICAL | 9.3 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos ... |
| CVE-2026-24457 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbit... |
| CVE-2026-30798 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-cl... |
| CVE-2026-30797 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An... |
| CVE-2026-30796 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client R... |
| CVE-2026-30795 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Wind... |
| CVE-2026-30794 | — | — | — | Mar 5, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-30793 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Li... |
| CVE-2026-30792 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (St... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now