2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4576 | LOW | 2.4 | 0.2% | Mar 23, 2026 | A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /a... |
| CVE-2026-4575 | LOW | 2.4 | 0.2% | Mar 23, 2026 | A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file ... |
| CVE-2026-4549 | LOW | 3.1 | 0.3% | Mar 22, 2026 | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPor... |
| CVE-2026-4115 | LOW | 3.7 | 0.5% | Mar 22, 2026 | A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the co... |
| CVE-2026-4541 | LOW | 2.5 | 0.1% | Mar 22, 2026 | A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_si... |
| CVE-2026-4539 | LOW | 3.3 | 0.2% | Mar 22, 2026 | A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file ... |
| CVE-2026-33550 | LOW | 2.6 | 0.1% | Mar 22, 2026 | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst... |
| CVE-2026-2290 | LOW | 3.8 | 0.3% | Mar 21, 2026 | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl... |
| CVE-2026-3339 | LOW | 2.7 | 0.4% | Mar 21, 2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including,... |
| CVE-2026-33426 | LOW | 3.8 | 0.2% | Mar 21, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users with... |
| CVE-2026-4495 | LOW | 3.5 | 0.3% | Mar 20, 2026 | A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/... |
| CVE-2026-4494 | LOW | 3.5 | 0.3% | Mar 20, 2026 | A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/... |
| CVE-2026-4519 | LOW | 3.3 | 0.3% | Mar 20, 2026 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer... |
| CVE-2026-32595 | LOW | 3.7 | 0.4% | Mar 20, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea... |
| CVE-2026-33081 | LOW | 3.7 | 0.3% | Mar 20, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below... |
| CVE-2026-4477 | LOW | 3.1 | 0.2% | Mar 20, 2026 | A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function ... |
| CVE-2026-32946 | LOW | 2.7 | 0.3% | Mar 20, 2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,... |
| CVE-2026-22735 | LOW | 2.6 | 0.1% | Mar 20, 2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue ... |
| CVE-2026-33408 | LOW | 2.7 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators... |
| CVE-2026-29104 | LOW | 2.7 | 0.2% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-4159 | LOW | 3.3 | 0.1% | Mar 19, 2026 | 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfS... |
| CVE-2026-33394 | LOW | 2.7 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E... |
| CVE-2026-3230 | LOW | 2.7 | 0.2% | Mar 19, 2026 | Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a c... |
| CVE-2026-32735 | LOW | 2.3 | 0.3% | Mar 18, 2026 | openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i... |
| CVE-2026-4407 | LOW | 2.1 | 0.1% | Mar 18, 2026 | Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now