2026 CVE Vulnerabilities
51,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30527 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ... |
| CVE-2026-5026 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without... |
| CVE-2026-5025 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log... |
| CVE-2026-5022 | MEDIUM | 5.3 | 0.2% | Mar 27, 2026 | The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a... |
| CVE-2026-5010 | MEDIUM | 5.1 | 0.3% | Mar 27, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attac... |
| CVE-2026-4980 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at... |
| CVE-2026-4954 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m... |
| CVE-2026-33766 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga... |
| CVE-2026-33764 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp... |
| CVE-2026-33763 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre... |
| CVE-2026-33761 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t... |
| CVE-2026-33759 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph... |
| CVE-2026-33758 | MEDIUM | 6.1 | 0.3% | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h... |
| CVE-2026-33284 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL... |
| CVE-2026-33206 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-33205 | MEDIUM | 5.5 | 0.2% | Mar 27, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.... |
| CVE-2026-30689 | MEDIUM | 4.3 | 0.4% | Mar 27, 2026 | In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive ... |
| CVE-2026-28375 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A testdata data-source can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-27879 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | A resample query can be used to trigger out-of-memory crashes in Grafana. |
| CVE-2026-32859 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts... |
| CVE-2026-4621 | MEDIUM | 5.6 | 0.2% | Mar 27, 2026 | Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network. |
| CVE-2026-4309 | MEDIUM | 6.5 | 0.1% | Mar 27, 2026 | Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor... |
| CVE-2026-25100 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker w... |
| CVE-2026-3457 | MEDIUM | 6.8 | 0.1% | Mar 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent... |
| CVE-2026-27860 | MEDIUM | 5.3 | 0.3% | Mar 27, 2026 | If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now