2026 CVE Vulnerabilities
51,016 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33635 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve... |
| CVE-2026-33628 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item ... |
| CVE-2026-33621 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` throug... |
| CVE-2026-33620 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug... |
| CVE-2026-33619 | MEDIUM | 5.5 | 0.2% | Mar 26, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains... |
| CVE-2026-33545 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m... |
| CVE-2026-33541 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati... |
| CVE-2026-33537 | MEDIUM | 5 | 0.3% | Mar 26, 2026 | Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from... |
| CVE-2026-33375 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest... |
| CVE-2026-2272 | MEDIUM | 6.5 | 0.8% | Mar 26, 2026 | A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the ... |
| CVE-2026-2271 | MEDIUM | 5.5 | 0.5% | Mar 26, 2026 | A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera... |
| CVE-2026-2239 | MEDIUM | 6.5 | 0.5% | Mar 26, 2026 | A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing ... |
| CVE-2026-21724 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API ... |
| CVE-2026-0967 | MEDIUM | 5.5 | 0.2% | Mar 26, 2026 | A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra... |
| CVE-2026-0964 | MEDIUM | 6.3 | 0.4% | Mar 26, 2026 | A malicious SCP server can send unexpected paths that could make the client application override local files outside of ... |
| CVE-2026-33536 | MEDIUM | 4.7 | 0.1% | Mar 26, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9... |
| CVE-2026-33535 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9... |
| CVE-2026-33532 | MEDIUM | 4.3 | 0.5% | Mar 26, 2026 | `yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branc... |
| CVE-2026-33531 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the r... |
| CVE-2026-33530 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with b... |
| CVE-2026-33528 | MEDIUM | 6.5 | 0.5% | Mar 26, 2026 | GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API end... |
| CVE-2026-33525 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2026-4923 | MEDIUM | 5.9 | 0.4% | Mar 26, 2026 | Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that... |
| CVE-2026-3190 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to ... |
| CVE-2026-33153 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now