2026 CVE Vulnerabilities
70,292 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3224 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear... |
| CVE-2026-3204 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers... |
| CVE-2026-3130 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker... |
| CVE-2026-2590 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions... |
| CVE-2026-27012 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri... |
| CVE-2026-25146 | HIGH | 8.1 | 0.4% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b... |
| CVE-2026-24898 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0,... |
| CVE-2026-24848 | CRITICAL | 9.9 | 6.8% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and ea... |
| CVE-2026-24415 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e... |
| CVE-2026-21866 | MEDIUM | 5.4 | 0.2% | Mar 3, 2026 | Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rend... |
| CVE-2026-1775 | HIGH | 8.8 | 0.8% | Mar 3, 2026 | The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac... |
| CVE-2026-3486 | HIGH | 7.2 | 0.3% | Mar 3, 2026 | A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2026-3485 | CRITICAL | 9.8 | 4.7% | Mar 3, 2026 | A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This... |
| CVE-2026-25906 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulne... |
| CVE-2026-24502 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit... |
| CVE-2026-1713 | MEDIUM | 5 | 0.1% | Mar 3, 2026 | IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 ... |
| CVE-2026-1567 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere... |
| CVE-2026-3494 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur... |
| CVE-2026-3484 | HIGH | 8.8 | 2.6% | Mar 3, 2026 | A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected ... |
| CVE-2026-2915 | HIGH | 7.1 | 0.1% | Mar 3, 2026 | HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability ... |
| CVE-2026-2606 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M... |
| CVE-2026-29022 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in th... |
| CVE-2026-26892 | HIGH | 7.2 | 0.3% | Mar 3, 2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php. |
| CVE-2026-26891 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php. |
| CVE-2026-26889 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now