2026 CVE Vulnerabilities
50,995 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26352 | MEDIUM | 5.4 | 0.1% | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/v... |
| CVE-2026-5170 | MEDIUM | 5.3 | 0.2% | Mar 30, 2026 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during... |
| CVE-2026-5123 | MEDIUM | 6.3 | 0.4% | Mar 30, 2026 | A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/pack... |
| CVE-2026-30561 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30560 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30559 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30558 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30557 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30556 | MEDIUM | 6.1 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-29597 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us... |
| CVE-2026-21712 | MEDIUM | 6.5 | 0.3% | Mar 30, 2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform... |
| CVE-2026-5164 | MEDIUM | 5.5 | 0.1% | Mar 30, 2026 | A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid... |
| CVE-2026-5122 | MEDIUM | 6.3 | 0.3% | Mar 30, 2026 | A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg... |
| CVE-2026-30566 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30565 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30564 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-30563 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerabi... |
| CVE-2026-30082 | MEDIUM | 6.1 | 0.2% | Mar 30, 2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngE... |
| CVE-2026-28528 | MEDIUM | 4.6 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET... |
| CVE-2026-28526 | MEDIUM | 5.7 | 0.1% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA... |
| CVE-2026-4315 | MEDIUM | 6.5 | 0.2% | Mar 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t... |
| CVE-2026-4266 | MEDIUM | 6.7 | 0.3% | Mar 30, 2026 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to... |
| CVE-2026-1612 | MEDIUM | 6.9 | 0.4% | Mar 30, 2026 | AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket... |
| CVE-2026-25704 | MEDIUM | 5.8 | 0.1% | Mar 30, 2026 | A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in cosmic-greete... |
| CVE-2026-5107 | MEDIUM | 4.2 | 0.3% | Mar 30, 2026 | A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now