2026 CVE Vulnerabilities
51,011 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4346 | MEDIUM | 6.8 | 0.1% | Mar 26, 2026 | The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of... |
| CVE-2026-33682 | MEDIUM | 4.8 | 0.3% | Mar 26, 2026 | Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.... |
| CVE-2026-33674 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation... |
| CVE-2026-33673 | MEDIUM | 5.4 | 0.3% | Mar 26, 2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros... |
| CVE-2026-33672 | MEDIUM | 5.3 | 0.4% | Mar 26, 2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj... |
| CVE-2026-33664 | MEDIUM | 5.4 | 0.3% | Mar 26, 2026 | Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied fl... |
| CVE-2026-33658 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33653 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis... |
| CVE-2026-1556 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 ... |
| CVE-2026-0748 | MEDIUM | 4.3 | 0.4% | Mar 26, 2026 | In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" ... |
| CVE-2026-4393 | MEDIUM | 4.3 | 0.1% | Mar 26, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue ... |
| CVE-2026-3532 | MEDIUM | 4.2 | 0.1% | Mar 26, 2026 | Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.... |
| CVE-2026-3531 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Au... |
| CVE-2026-3530 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forg... |
| CVE-2026-3529 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Anal... |
| CVE-2026-3528 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation... |
| CVE-2026-3527 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Config... |
| CVE-2026-3526 | MEDIUM | 5.3 | 0.3% | Mar 26, 2026 | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects... |
| CVE-2026-3525 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects... |
| CVE-2026-33742 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fiel... |
| CVE-2026-33738 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored wit... |
| CVE-2026-33644 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` c... |
| CVE-2026-33638 | MEDIUM | 5.3 | 0.5% | Mar 26, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all... |
| CVE-2026-33635 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve... |
| CVE-2026-33628 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now