2026 CVE Vulnerabilities
70,292 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2746 | MEDIUM | 5.3 | 0.2% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, le... |
| CVE-2026-27446 | CRITICAL | 9.8 | 10.0% | Mar 4, 2026 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unau... |
| CVE-2026-27445 | MEDIUM | 5.3 | 0.1% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the e... |
| CVE-2026-27444 | HIGH | 7.5 | 0.2% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing... |
| CVE-2026-27443 | HIGH | 7.5 | 0.2% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME en... |
| CVE-2026-27442 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenam... |
| CVE-2026-27441 | CRITICAL | 9.8 | 0.3% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS ... |
| CVE-2026-1236 | MEDIUM | 6.4 | 0.2% | Mar 4, 2026 | The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_ga... |
| CVE-2026-29120 | HIGH | 7.8 | 0.1% | Mar 4, 2026 | The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2... |
| CVE-2026-29119 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insec... |
| CVE-2026-28778 | CRITICAL | 9.8 | 0.8% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/ins... |
| CVE-2026-28777 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account.... |
| CVE-2026-28776 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for th... |
| CVE-2026-28775 | CRITICAL | 9.8 | 1.2% | Mar 4, 2026 | An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor... |
| CVE-2026-28774 | HIGH | 8.8 | 2.4% | Mar 4, 2026 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting... |
| CVE-2026-28773 | HIGH | 8.8 | 2.1% | Mar 4, 2026 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup... |
| CVE-2026-28772 | MEDIUM | 6.1 | 0.2% | Mar 4, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting... |
| CVE-2026-28771 | MEDIUM | 6.1 | 0.2% | Mar 4, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corp... |
| CVE-2026-2732 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa... |
| CVE-2026-2363 | MEDIUM | 6.5 | 0.3% | Mar 4, 2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the... |
| CVE-2026-28770 | HIGH | 8.8 | 0.4% | Mar 4, 2026 | Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp... |
| CVE-2026-28769 | MEDIUM | 6.5 | 0.6% | Mar 4, 2026 | A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporatio... |
| CVE-2026-2025 | HIGH | 7.5 | 1.4% | Mar 4, 2026 | The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unau... |
| CVE-2026-3242 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block. The Concre... |
| CVE-2026-3241 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now