2026 CVE Vulnerabilities
50,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4992 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op... |
| CVE-2026-4991 | MEDIUM | 5.1 | 0.2% | Mar 27, 2026 | A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct... |
| CVE-2026-33996 | MEDIUM | 5.5 | 0.1% | Mar 27, 2026 | LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS ... |
| CVE-2026-33992 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e... |
| CVE-2026-33936 | MEDIUM | 5.3 | 0.5% | Mar 27, 2026 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El... |
| CVE-2026-4988 | MEDIUM | 5.9 | 0.6% | Mar 27, 2026 | A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6... |
| CVE-2026-4985 | MEDIUM | 5.3 | 0.5% | Mar 27, 2026 | A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the ... |
| CVE-2026-33989 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp... |
| CVE-2026-33981 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include... |
| CVE-2026-33954 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-... |
| CVE-2026-33946 | MEDIUM | 5.9 | 0.5% | Mar 27, 2026 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S... |
| CVE-2026-33916 | MEDIUM | 4.7 | 0.2% | Mar 27, 2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve... |
| CVE-2026-33907 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo... |
| CVE-2026-33904 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification ... |
| CVE-2026-33903 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted ... |
| CVE-2026-33887 | MEDIUM | 5.4 | 0.1% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticate... |
| CVE-2026-33886 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions ... |
| CVE-2026-33885 | MEDIUM | 6.1 | 0.2% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external... |
| CVE-2026-33884 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic... |
| CVE-2026-33883 | MEDIUM | 6.1 | 0.1% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:re... |
| CVE-2026-33882 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown... |
| CVE-2026-4971 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip... |
| CVE-2026-34389 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w... |
| CVE-2026-33869 | MEDIUM | 4.8 | 0.2% | Mar 27, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5... |
| CVE-2026-33868 | MEDIUM | 6.1 | 0.5% | Mar 27, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now