2026 CVE Vulnerabilities
51,094 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21790 | MEDIUM | 6.3 | 0.1% | Mar 24, 2026 | HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to byp... |
| CVE-2026-33353 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authoriza... |
| CVE-2026-33349 | MEDIUM | 5.9 | 0.4% | Mar 24, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.... |
| CVE-2026-33347 | MEDIUM | 6.1 | 0.2% | Mar 24, 2026 | league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in th... |
| CVE-2026-33345 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza... |
| CVE-2026-33331 | MEDIUM | 5.4 | 0.3% | Mar 24, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.... |
| CVE-2026-33326 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be ... |
| CVE-2026-33314 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoof... |
| CVE-2026-21783 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provid... |
| CVE-2026-33769 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path... |
| CVE-2026-33627 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33527 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33429 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33421 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33323 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-23924 | MEDIUM | 6.1 | 0.3% | Mar 24, 2026 | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t... |
| CVE-2026-23923 | MEDIUM | 6.9 | 0.3% | Mar 24, 2026 | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The... |
| CVE-2026-33401 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in c... |
| CVE-2026-33400 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scrip... |
| CVE-2026-33162 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control pa... |
| CVE-2026-33161 | MEDIUM | 4.3 | 0.2% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R... |
| CVE-2026-33160 | MEDIUM | 5.3 | 0.4% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R... |
| CVE-2026-33159 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R... |
| CVE-2026-33158 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R... |
| CVE-2026-33700 | MEDIUM | 4.9 | 0.2% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now