2026 CVE Vulnerabilities
70,424 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0689 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an ... |
| CVE-2026-26703 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php... |
| CVE-2026-26702 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. |
| CVE-2026-26696 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. |
| CVE-2026-26695 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. |
| CVE-2026-26694 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. |
| CVE-2026-24115 | CRITICAL | 9.8 | 0.7% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before co... |
| CVE-2026-24114 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflow... |
| CVE-2026-24113 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu... |
| CVE-2026-24111 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value... |
| CVE-2026-24109 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu... |
| CVE-2026-24108 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the valu... |
| CVE-2026-24107 | CRITICAL | 9.8 | 2.2% | Mar 2, 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is d... |
| CVE-2026-23600 | CRITICAL | 9.8 | 1.0% | Mar 2, 2026 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). |
| CVE-2026-0995 | LOW | 3.6 | 0.1% | Mar 2, 2026 | An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to... |
| CVE-2026-26698 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php. |
| CVE-2026-26697 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?te... |
| CVE-2026-1628 | MEDIUM | 4.6 | 0.1% | Mar 2, 2026 | Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma... |
| CVE-2026-3432 | CRITICAL | 9.1 | 0.3% | Mar 2, 2026 | On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all author... |
| CVE-2026-3431 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller ... |
| CVE-2026-2584 | CRITICAL | 9.3 | 0.4% | Mar 2, 2026 | A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe... |
| CVE-2026-20445 | MEDIUM | 4.4 | 0.1% | Mar 2, 2026 | In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic... |
| CVE-2026-20444 | MEDIUM | 6.7 | 0.1% | Mar 2, 2026 | In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of ... |
| CVE-2026-20443 | MEDIUM | 6.7 | 0.1% | Mar 2, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2026-20442 | MEDIUM | 4.4 | 0.1% | Mar 2, 2026 | In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now