2026 CVE Vulnerabilities
70,360 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3136 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allow... |
| CVE-2026-26886 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_servic... |
| CVE-2026-26885 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_... |
| CVE-2026-26884 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view... |
| CVE-2026-26883 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de... |
| CVE-2026-3465 | LOW | 3.1 | 0.3% | Mar 3, 2026 | A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun... |
| CVE-2026-2637 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T... |
| CVE-2026-28518 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack impo... |
| CVE-2026-25674 | LOW | 3.7 | 0.3% | Mar 3, 2026 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto... |
| CVE-2026-25673 | HIGH | 7.5 | 0.7% | Mar 3, 2026 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django ... |
| CVE-2026-24103 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi. |
| CVE-2026-22891 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig... |
| CVE-2026-20777 | HIGH | 8.1 | 0.5% | Mar 3, 2026 | A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbios... |
| CVE-2026-3344 | MEDIUM | 4.9 | 0.3% | Mar 3, 2026 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and... |
| CVE-2026-3343 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript... |
| CVE-2026-3342 | HIGH | 7.2 | 0.8% | Mar 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to ex... |
| CVE-2026-3351 | MEDIUM | 4.3 | 0.1% | Mar 3, 2026 | Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, ... |
| CVE-2026-3463 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer:... |
| CVE-2026-2568 | HIGH | 7.2 | 0.2% | Mar 3, 2026 | The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to ... |
| CVE-2026-22886 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product... |
| CVE-2026-1876 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Et... |
| CVE-2026-1875 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherN... |
| CVE-2026-1874 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE... |
| CVE-2026-3455 | MEDIUM | 6.1 | 0.3% | Mar 3, 2026 | Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi... |
| CVE-2026-3449 | LOW | 3.3 | 0.1% | Mar 3, 2026 | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resol... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now