2026 CVE Vulnerabilities
70,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2833 | CRITICAL | 9.1 | 0.7% | Mar 5, 2026 | An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The i... |
| CVE-2026-22052 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success... |
| CVE-2026-2297 | MEDIUM | 5.7 | 0.2% | Mar 4, 2026 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (... |
| CVE-2026-29086 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCo... |
| CVE-2026-29085 | MEDIUM | 6.5 | 0.2% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin... |
| CVE-2026-29045 | CRITICAL | 9.8 | 0.4% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin... |
| CVE-2026-26002 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4... |
| CVE-2026-29000 | CRITICAL | 9.1 | 0.5% | Mar 4, 2026 | pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator w... |
| CVE-2026-27898 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-27803 | HIGH | 8.3 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-27802 | HIGH | 8.3 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-27801 | MEDIUM | 5.9 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve... |
| CVE-2026-25750 | HIGH | 8.1 | 0.3% | Mar 4, 2026 | Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm ver... |
| CVE-2026-22040 | MEDIUM | 5.3 | 0.2% | Mar 4, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffi... |
| CVE-2026-3545 | CRITICAL | 9.6 | 0.3% | Mar 4, 2026 | Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti... |
| CVE-2026-3544 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out o... |
| CVE-2026-3543 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially per... |
| CVE-2026-3542 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perfor... |
| CVE-2026-3541 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out... |
| CVE-2026-3540 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform o... |
| CVE-2026-3539 | — | — | — | Mar 4, 2026 | Rejected reason: Determined a bug and not a vulnerability |
| CVE-2026-3538 | HIGH | 8.8 | 0.4% | Mar 4, 2026 | Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out o... |
| CVE-2026-3537 | HIGH | 8.8 | 0.4% | Mar 4, 2026 | Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to poten... |
| CVE-2026-3536 | HIGH | 8.8 | 0.5% | Mar 4, 2026 | Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out ... |
| CVE-2026-28435 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now