2026 CVE Vulnerabilities
51,085 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20692 | MEDIUM | 5.3 | 0.4% | Mar 25, 2026 | A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.... |
| CVE-2026-20691 | MEDIUM | 4.3 | 0.3% | Mar 25, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iP... |
| CVE-2026-20690 | MEDIUM | 6.5 | 0.7% | Mar 25, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS ... |
| CVE-2026-20686 | MEDIUM | 5.3 | 0.2% | Mar 25, 2026 | This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be ... |
| CVE-2026-20670 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ... |
| CVE-2026-20668 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.... |
| CVE-2026-20665 | MEDIUM | 6.5 | 0.6% | Mar 25, 2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18... |
| CVE-2026-20664 | MEDIUM | 4.3 | 0.7% | Mar 25, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, mac... |
| CVE-2026-20657 | MEDIUM | 6.5 | 0.5% | Mar 25, 2026 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7... |
| CVE-2026-20651 | MEDIUM | 6.2 | 0.2% | Mar 25, 2026 | A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, ma... |
| CVE-2026-20637 | MEDIUM | 6.2 | 0.2% | Mar 25, 2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.... |
| CVE-2026-20633 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1... |
| CVE-2026-20632 | MEDIUM | 5.3 | 0.3% | Mar 25, 2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2026-20607 | MEDIUM | 4 | 0.2% | Mar 25, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom... |
| CVE-2026-4778 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code... |
| CVE-2026-4777 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of th... |
| CVE-2026-4433 | MEDIUM | 4.3 | 0.2% | Mar 24, 2026 | An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service inform... |
| CVE-2026-3889 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. |
| CVE-2026-33215 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides... |
| CVE-2026-21790 | MEDIUM | 6.3 | 0.1% | Mar 24, 2026 | HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to byp... |
| CVE-2026-33353 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authoriza... |
| CVE-2026-33349 | MEDIUM | 5.9 | 0.4% | Mar 24, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.... |
| CVE-2026-33347 | MEDIUM | 6.1 | 0.2% | Mar 24, 2026 | league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in th... |
| CVE-2026-33345 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza... |
| CVE-2026-33331 | MEDIUM | 5.4 | 0.3% | Mar 24, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now