2026 CVE Vulnerabilities
51,002 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27859 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma... |
| CVE-2026-27856 | MEDIUM | 5.9 | 0.4% | Mar 27, 2026 | Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u... |
| CVE-2026-27855 | MEDIUM | 5.9 | 0.3% | Mar 27, 2026 | Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern... |
| CVE-2026-0394 | MEDIUM | 5.3 | 0.4% | Mar 27, 2026 | When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s... |
| CVE-2026-4948 | MEDIUM | 5.5 | 0.1% | Mar 27, 2026 | A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D... |
| CVE-2026-34353 | MEDIUM | 5.1 | 0.1% | Mar 27, 2026 | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un... |
| CVE-2026-33559 | MEDIUM | 5.4 | 0.2% | Mar 27, 2026 | WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the af... |
| CVE-2026-33366 | MEDIUM | 6.9 | 0.3% | Mar 27, 2026 | Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for... |
| CVE-2026-3098 | MEDIUM | 6.5 | 0.5% | Mar 27, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1... |
| CVE-2026-4907 | MEDIUM | 6.3 | 0.2% | Mar 27, 2026 | A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted... |
| CVE-2026-33730 | MEDIUM | 6.5 | 0.3% | Mar 27, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2026-33726 | MEDIUM | 4.3 | 0.2% | Mar 27, 2026 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.... |
| CVE-2026-33693 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in... |
| CVE-2026-33697 | MEDIUM | 6.3 | 0.1% | Mar 27, 2026 | Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner... |
| CVE-2026-29071 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-28786 | MEDIUM | 4.3 | 0.4% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-33743 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac... |
| CVE-2026-33542 | MEDIUM | 4.8 | 0.2% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing... |
| CVE-2026-4900 | MEDIUM | 5.5 | 0.4% | Mar 26, 2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2026-4898 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un... |
| CVE-2026-4346 | MEDIUM | 6.8 | 0.1% | Mar 26, 2026 | The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of... |
| CVE-2026-33682 | MEDIUM | 4.8 | 0.3% | Mar 26, 2026 | Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.... |
| CVE-2026-33674 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation... |
| CVE-2026-33673 | MEDIUM | 5.4 | 0.3% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros... |
| CVE-2026-33672 | MEDIUM | 5.3 | 0.4% | Mar 26, 2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now