2026 CVE Vulnerabilities
70,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22397 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22395 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22394 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22392 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22390 | CRITICAL | 9.9 | 0.5% | Mar 5, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress b... |
| CVE-2026-22389 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22387 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22385 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-3523 | MEDIUM | 4.9 | 0.5% | Mar 5, 2026 | The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, ... |
| CVE-2026-3034 | MEDIUM | 6.4 | 0.2% | Mar 5, 2026 | The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera... |
| CVE-2026-2899 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ... |
| CVE-2026-2365 | HIGH | 7.2 | 0.3% | Mar 5, 2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav... |
| CVE-2026-29127 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. ... |
| CVE-2026-26034 | HIGH | 8.5 | 0.2% | Mar 5, 2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vul... |
| CVE-2026-26033 | HIGH | 8.4 | 0.2% | Mar 5, 2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) v... |
| CVE-2026-3381 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib incl... |
| CVE-2026-3257 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl emb... |
| CVE-2026-29126 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) ... |
| CVE-2026-29125 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS reso... |
| CVE-2026-29124 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DP... |
| CVE-2026-29123 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a l... |
| CVE-2026-29122 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid... |
| CVE-2026-29121 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid ... |
| CVE-2026-2836 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The... |
| CVE-2026-2835 | CRITICAL | 9.1 | 0.7% | Mar 5, 2026 | An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now