2026 CVE Vulnerabilities
50,987 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30879 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability i... |
| CVE-2026-30878 | MEDIUM | 5.3 | 0.4% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated... |
| CVE-2026-5157 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the ... |
| CVE-2026-33995 | MEDIUM | 5.3 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in... |
| CVE-2026-33987 | MEDIUM | 6.6 | 0.1% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry... |
| CVE-2026-33983 | MEDIUM | 6.5 | 0.4% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_up... |
| CVE-2026-33977 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra... |
| CVE-2026-33952 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie... |
| CVE-2026-32794 | MEDIUM | 4.8 | 0.4% | Mar 30, 2026 | Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate ... |
| CVE-2026-32884 | MEDIUM | 5.9 | 0.2% | Mar 30, 2026 | Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name ... |
| CVE-2026-32883 | MEDIUM | 5.9 | 0.2% | Mar 30, 2026 | Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP resp... |
| CVE-2026-5148 | MEDIUM | 4.7 | 0.3% | Mar 30, 2026 | A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file ... |
| CVE-2026-31804 | MEDIUM | 5.3 | 0.3% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_p... |
| CVE-2026-31799 | MEDIUM | 4.9 | 0.4% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.1... |
| CVE-2026-21717 | MEDIUM | 5.9 | 0.3% | Mar 30, 2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col... |
| CVE-2026-21714 | MEDIUM | 5.3 | 0.5% | Mar 30, 2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t... |
| CVE-2026-21713 | MEDIUM | 5.9 | 0.4% | Mar 30, 2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent... |
| CVE-2026-21711 | MEDIUM | 5.3 | 0.1% | Mar 30, 2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req... |
| CVE-2026-5126 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. T... |
| CVE-2026-5125 | MEDIUM | 5.3 | 0.8% | Mar 30, 2026 | A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_... |
| CVE-2026-33029 | MEDIUM | 6.5 | 0.9% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in ... |
| CVE-2026-33027 | MEDIUM | 6.5 | 0.4% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly... |
| CVE-2026-5124 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes... |
| CVE-2026-29909 | MEDIUM | 5.3 | 0.4% | Mar 30, 2026 | MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/f... |
| CVE-2026-27508 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redire... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now