2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22629 | LOW | 3.7 | 0.4% | Mar 10, 2026 | An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4... |
| CVE-2026-21791 | LOW | 3.3 | 0.1% | Mar 10, 2026 | HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica... |
| CVE-2026-3706 | LOW | 3.7 | 0.2% | Mar 8, 2026 | A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25... |
| CVE-2026-3671 | LOW | 3.3 | 0.1% | Mar 7, 2026 | A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalan... |
| CVE-2026-2671 | LOW | 3.1 | 0.2% | Mar 7, 2026 | A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionali... |
| CVE-2026-30848 | LOW | 3.7 | 0.3% | Mar 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-3668 | LOW | 3.1 | 0.3% | Mar 7, 2026 | A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the... |
| CVE-2026-29185 | LOW | 2.7 | 0.3% | Mar 7, 2026 | Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL p... |
| CVE-2026-27139 | LOW | 2.5 | 0.2% | Mar 6, 2026 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou... |
| CVE-2026-28475 | LOW | 3.7 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28540 | LOW | 3.3 | 0.1% | Mar 5, 2026 | Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-21786 | LOW | 3.3 | 0.1% | Mar 5, 2026 | HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application... |
| CVE-2026-23811 | LOW | 3.1 | 0.2% | Mar 4, 2026 | A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction... |
| CVE-2026-23810 | LOW | 3.1 | 0.2% | Mar 4, 2026 | A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-... |
| CVE-2026-26891 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php. |
| CVE-2026-26889 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php. |
| CVE-2026-26888 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php. |
| CVE-2026-26887 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php. |
| CVE-2026-26890 | LOW | 2.7 | 0.3% | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php. |
| CVE-2026-26886 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_servic... |
| CVE-2026-26885 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_... |
| CVE-2026-26884 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view... |
| CVE-2026-26883 | LOW | 2.7 | 0.2% | Mar 3, 2026 | Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de... |
| CVE-2026-3465 | LOW | 3.1 | 0.3% | Mar 3, 2026 | A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun... |
| CVE-2026-25674 | LOW | 3.7 | 0.3% | Mar 3, 2026 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now