2026 CVE Vulnerabilities
51,024 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4923 | MEDIUM | 5.9 | 0.4% | Mar 26, 2026 | Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that... |
| CVE-2026-3190 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to ... |
| CVE-2026-33153 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t... |
| CVE-2026-33148 | MEDIUM | 6.5 | 0.5% | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t... |
| CVE-2026-29969 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attac... |
| CVE-2026-29055 | MEDIUM | 5.3 | 0.3% | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t... |
| CVE-2026-28503 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t... |
| CVE-2026-33732 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `F... |
| CVE-2026-33495 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o... |
| CVE-2026-33490 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `sta... |
| CVE-2026-33486 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulne... |
| CVE-2026-33481 | MEDIUM | 5.3 | 0.4% | Mar 26, 2026 | Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys... |
| CVE-2026-33477 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.... |
| CVE-2026-3116 | MEDIUM | 4.9 | 0.3% | Mar 26, 2026 | Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows a... |
| CVE-2026-3115 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restric... |
| CVE-2026-3114 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompres... |
| CVE-2026-3113 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on... |
| CVE-2026-3112 | MEDIUM | 4.9 | 0.4% | Mar 26, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced ... |
| CVE-2026-34071 | MEDIUM | 6.1 | 0.3% | Mar 26, 2026 | Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version ... |
| CVE-2026-33470 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-... |
| CVE-2026-33469 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an aut... |
| CVE-2026-33438 | MEDIUM | 6.5 | 0.4% | Mar 26, 2026 | Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions st... |
| CVE-2026-33402 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titl... |
| CVE-2026-33015 | MEDIUM | 5.2 | 0.2% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop ... |
| CVE-2026-33014 | MEDIUM | 5.2 | 0.2% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now