2026 CVE Vulnerabilities
70,363 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1874 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE... |
| CVE-2026-3455 | MEDIUM | 6.1 | 0.3% | Mar 3, 2026 | Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi... |
| CVE-2026-3449 | LOW | 3.3 | 0.1% | Mar 3, 2026 | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resol... |
| CVE-2026-1492 | CRITICAL | 9.8 | 25.5% | Mar 3, 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2026-20801 | MEDIUM | 5.6 | 0.1% | Mar 3, 2026 | Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher ... |
| CVE-2026-20757 | LOW | 2.5 | 0.1% | Mar 3, 2026 | Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited... |
| CVE-2026-2628 | CRITICAL | 9.8 | 0.9% | Mar 3, 2026 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass... |
| CVE-2026-2448 | HIGH | 8.8 | 0.9% | Mar 3, 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... |
| CVE-2026-2269 | HIGH | 7.2 | 0.7% | Mar 3, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2026-1487 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2026-0754 | HIGH | 8.2 | 0.1% | Mar 3, 2026 | An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering t... |
| CVE-2026-1566 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege esca... |
| CVE-2026-1336 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m... |
| CVE-2026-2583 | MEDIUM | 6.4 | 0.2% | Mar 2, 2026 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a... |
| CVE-2026-3338 | HIGH | 8.7 | 0.8% | Mar 2, 2026 | Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio... |
| CVE-2026-3337 | HIGH | 8.2 | 1.1% | Mar 2, 2026 | Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au... |
| CVE-2026-3336 | HIGH | 8.7 | 0.8% | Mar 2, 2026 | Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v... |
| CVE-2026-2256 | MEDIUM | 6.5 | 1.6% | Mar 2, 2026 | A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker t... |
| CVE-2026-27631 | MEDIUM | 5.3 | 0.3% | Mar 2, 2026 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2026-27596 | HIGH | 7.5 | 0.4% | Mar 2, 2026 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2026-26713 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. |
| CVE-2026-26712 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. |
| CVE-2026-25884 | HIGH | 8.1 | 0.3% | Mar 2, 2026 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2026-25477 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redire... |
| CVE-2026-21882 | HIGH | 8.4 | 0.2% | Mar 2, 2026 | theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now