2026 CVE Vulnerabilities
70,367 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28360 | MEDIUM | 5.3 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i... |
| CVE-2026-28359 | MEDIUM | 5.4 | 0.1% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor r... |
| CVE-2026-28358 | MEDIUM | 5.3 | 0.6% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return... |
| CVE-2026-28357 | MEDIUM | 5.4 | 0.1% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists i... |
| CVE-2026-28286 | CRITICAL | 9.9 | 0.4% | Mar 2, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, t... |
| CVE-2026-26708 | CRITICAL | 9.8 | 0.3% | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. |
| CVE-2026-26700 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php. |
| CVE-2026-24105 | CRITICAL | 9.8 | 1.7% | Mar 2, 2026 | An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not check... |
| CVE-2026-23865 | MEDIUM | 5.3 | 0.1% | Mar 2, 2026 | An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13... |
| CVE-2026-21385 | HIGH | 7.8 | 1.1% | Mar 2, 2026 | Memory corruption while using alignments for memory allocation. |
| CVE-2026-28412 | HIGH | 7.5 | 0.3% | Mar 2, 2026 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limi... |
| CVE-2026-28403 | HIGH | 7.6 | 0.1% | Mar 2, 2026 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.... |
| CVE-2026-26720 | CRITICAL | 9.8 | 0.8% | Mar 2, 2026 | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod... |
| CVE-2026-26701 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user... |
| CVE-2026-26699 | HIGH | 7.2 | 0.6% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin... |
| CVE-2026-24112 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value... |
| CVE-2026-24110 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these ... |
| CVE-2026-24101 | CRITICAL | 9.8 | 1.7% | Mar 2, 2026 | An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` wi... |
| CVE-2026-0689 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an ... |
| CVE-2026-26703 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php... |
| CVE-2026-26702 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. |
| CVE-2026-26696 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. |
| CVE-2026-26695 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. |
| CVE-2026-26694 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. |
| CVE-2026-24115 | CRITICAL | 9.8 | 0.7% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now